mirror of
https://github.com/django/django.git
synced 2025-10-31 09:41:08 +00:00
Fixed CVE-2022-41323 -- Prevented locales being interpreted as regular expressions.
Thanks to Benjamin Balder Bach for the report.
This commit is contained in:
committed by
Carlton Gibson
parent
4771a1694b
commit
e5ea284294
@@ -7,6 +7,12 @@ Django 4.1.2 release notes
|
||||
Django 4.1.2 fixes a security issue with severity "medium" and several bugs in
|
||||
4.1.1.
|
||||
|
||||
CVE-2022-41323: Potential denial-of-service vulnerability in internationalized URLs
|
||||
===================================================================================
|
||||
|
||||
Internationalized URLs were subject to potential denial of service attack via
|
||||
the locale parameter.
|
||||
|
||||
Bugfixes
|
||||
========
|
||||
|
||||
|
||||
Reference in New Issue
Block a user