diff --git a/docs/releases/security.txt b/docs/releases/security.txt index cbd5585244..ddb4871a7b 100644 --- a/docs/releases/security.txt +++ b/docs/releases/security.txt @@ -690,3 +690,15 @@ Versions affected * Django 1.8 `(patch) `__ * Django 1.7 `(patch) `__ + +February 1, 2016 -- CVE-2016-2048 +--------------------------------- + +`CVE-2016-2048 `_: +User with "change" but not "add" permission can create objects for ``ModelAdmin``’s with ``save_as=True``. +`Full description `__ + +Versions affected +~~~~~~~~~~~~~~~~~ + +* Django 1.9 `(patch) `__