diff --git a/docs/releases/security.txt b/docs/releases/security.txt index f6f2534baa..28b4f37afc 100644 --- a/docs/releases/security.txt +++ b/docs/releases/security.txt @@ -692,3 +692,15 @@ Versions affected * Django 1.8 `(patch) `__ * Django 1.7 `(patch) `__ + +February 1, 2016 -- CVE-2016-2048 +--------------------------------- + +`CVE-2016-2048 `_: +User with "change" but not "add" permission can create objects for ``ModelAdmin``’s with ``save_as=True``. +`Full description `__ + +Versions affected +~~~~~~~~~~~~~~~~~ + +* Django 1.9 `(patch) `__