From a1dd78513980873be882cb75481ea6e9e2cb6212 Mon Sep 17 00:00:00 2001 From: Mariusz Felisiak Date: Mon, 4 Sep 2023 13:09:48 +0200 Subject: [PATCH] [4.2.x] Added CVE-2023-41164 to security archive. Backport of 8a98768868a104ea3ce10d8182590bdd095d9ccb from main --- docs/releases/security.txt | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/docs/releases/security.txt b/docs/releases/security.txt index 48586c8a6e..34394c50b0 100644 --- a/docs/releases/security.txt +++ b/docs/releases/security.txt @@ -36,6 +36,17 @@ Issues under Django's security process All security issues have been handled under versions of Django's security process. These are listed below. +September 4, 2023 - :cve:`2023-41164` +------------------------------------- + +Potential denial of service vulnerability in +``django.utils.encoding.uri_to_iri()``. `Full description +`__ + +* Django 4.2 :commit:`(patch) <9c51b4dcfa0cefcb48231f4d71cafa80821f87b9>` +* Django 4.1 :commit:`(patch) ` +* Django 3.2 :commit:`(patch) <6f030b1149bd8fa4ba90452e77cb3edc095ce54e>` + July 3, 2023 - :cve:`2023-36053` --------------------------------