==========================Django 1.4.7 release notes==========================*September 10, 2013*Django 1.4.7 fixes one security issue present in previous Django releases inthe 1.4 series.Directory traversal vulnerability in ``ssi`` template tag=========================================================In previous versions of Django it was possible to bypass the``ALLOWED_INCLUDE_ROOTS`` setting used for security with the ``ssi``template tag by specifying a relative path that starts with one of the allowedroots. For example, if ``ALLOWED_INCLUDE_ROOTS = ("/var/www",)`` the followingwould be possible:.. code-block:: html+django{% ssi "/var/www/../../etc/passwd" %}In practice this is not a very common problem, as it would require the templateauthor to put the ``ssi`` file in a user-controlled variable, but it'spossible in principle.