Shai Berger
072963e4c4
[3.2.x] Fixed CVE-2024-27351 -- Prevented potential ReDoS in Truncator.words().
...
Thanks Seokchan Yoon for the report.
Co-Authored-By: Mariusz Felisiak <felisiak.mariusz@gmail.com>
2024-03-04 08:37:38 +01:00
Mariusz Felisiak
2ad2676456
[3.2.x] Added release date for 3.2.25.
...
Backport of 977d25416954a72ad100b01762078bf1ceb89a63 from main
2024-02-26 08:30:32 +01:00
Mariusz Felisiak
fc41af69a2
[3.2.x] Fixed #35172 -- Fixed intcomma for string floats.
...
Thanks Warwick Brown for the report.
Regression in 55519d6cf8998fe4c8f5c8abffc2b10a7c3d14e9.
Backport of 2f14c2cedc9c92373471c1f98a80c81ba299584a from main.
2024-02-08 11:03:21 +01:00
Natalia
b9170b4a9e
[3.2.x] Added CVE-2024-24680 to security archive.
...
Backport of c650c1412d1933e339cc93f9b6745c3eedb1c25b from main
2024-02-06 12:17:11 -03:00
Natalia
e5350a931a
[3.2.x] Post release version bump.
2024-02-06 10:39:23 -03:00
Natalia
f5c880857e
[3.2.x] Bumped version for 3.2.24 release.
3.2.24
2024-02-06 10:32:27 -03:00
Adam Johnson
c1171ffbd5
[3.2.x] Fixed CVE-2024-24680 -- Mitigated potential DoS in intcomma template filter.
...
Thanks Seokchan Yoon for the report.
Co-authored-by: Mariusz Felisiak <felisiak.mariusz@gmail.com>
Co-authored-by: Natalia <124304+nessita@users.noreply.github.com>
Co-authored-by: Shai Berger <shai@platonix.com>
2024-02-06 10:28:51 -03:00
Natalia
9dc345643e
[3.2.x] Added stub release notes 3.2.24.
...
Backport of 06d0a1bd56a9899c351ca047a05813e8dd6a4e17 from main
2024-01-29 11:55:24 -03:00
Denys Halenok
90eae45b38
[3.2.x] Fixed documented alias of smart_text().
2024-01-11 20:16:20 +01:00
Mariusz Felisiak
c9ad858033
[3.2.x] Pinned python-memcached == 1.59 in test requirements.
...
python-memcached 1.60 made breaking changes, e.g. _deletetouch() has
been removed.
2023-12-27 14:22:20 +01:00
Mariusz Felisiak
12b685c61f
[3.2.x] Added CVE-2023-46695 to security archive.
...
Backport of 7caf2621833a45cdfe7e6e305e4885ecc8d79744 from main
2023-11-01 08:18:33 +01:00
Mariusz Felisiak
0059182643
[3.2.x] Post-release version bump.
2023-11-01 06:34:10 +01:00
Mariusz Felisiak
60e648a7ae
[3.2.x] Bumped version for 3.2.23 release.
3.2.23
2023-11-01 06:31:51 +01:00
Mariusz Felisiak
f9a7fb8466
[3.2.x] Fixed CVE-2023-46695 -- Fixed potential DoS in UsernameField on Windows.
...
Thanks MProgrammer (https://hackerone.com/mprogrammer ) for the report.
2023-11-01 06:30:59 +01:00
Mariusz Felisiak
e6d2591d9e
[3.2.x] Added stub release notes for 3.2.23.
...
Backport of fdd1323b9c83e56184e0c992af8faf8d54327775 from main.
2023-10-25 05:47:09 +02:00
Natalia
3c04b74293
[3.2.x] Added CVE-2023-43665 to security archive.
...
Backport of 4e790271e3e65c9ad037b347a34fa95e11982228 from main
2023-10-04 13:11:42 -03:00
Natalia
86a14d653f
[3.2.x] Post release version bump.
2023-10-04 10:57:29 -03:00
Natalia
3106e94e52
[3.2.x] Bumped version for 3.2.22 release.
3.2.22
2023-10-04 10:34:56 -03:00
Natalia
ccdade1a02
[3.2.x] Fixed CVE-2023-43665 -- Mitigated potential DoS in django.utils.text.Truncator when truncating HTML text.
...
Thanks Wenchao Li of Alibaba Group for the report.
2023-10-04 09:41:12 -03:00
Natalia
6caf7b313d
[3.2.x] Added stub release notes for 3.2.22.
...
Backport of 24f1a38b37c0af3a5ce0dd7b5392fe4e75d7e1dc from main.
2023-09-27 14:34:57 -03:00
Mariusz Felisiak
9e814c3a5e
[3.2.x] Added CVE-2023-41164 to security archive.
...
Backport of 8a98768868a104ea3ce10d8182590bdd095d9ccb from main
2023-09-04 13:18:49 +02:00
Mariusz Felisiak
4b439dcd05
[3.2.x] Post-release version bump.
2023-09-04 12:25:28 +02:00
Mariusz Felisiak
fd0ccd7fb3
[3.2.x] Bumped version for 3.2.21 release.
3.2.21
2023-09-04 12:23:57 +02:00
Mariusz Felisiak
6f030b1149
[3.2.x] Fixed CVE-2023-41164 -- Fixed potential DoS in django.utils.encoding.uri_to_iri().
...
Thanks MProgrammer (https://hackerone.com/mprogrammer ) for the report.
Co-authored-by: nessita <124304+nessita@users.noreply.github.com>
2023-09-04 12:23:18 +02:00
Mariusz Felisiak
73350a6369
[3.2.x] Added stub release notes for 3.2.21.
...
Backport of 24f1a38b37c0af3a5ce0dd7b5392fe4e75d7e1dc from main.
2023-08-28 06:19:18 +02:00
David Smith
75418f8c0e
[3.2.x] Fixed #34756 -- Fixed docs HTML build on Sphinx 7.1+.
...
Backport of b3e0170ab546a96930ce3114b0a1a560953c0ff4 from main
2023-08-03 09:38:10 +02:00
Mariusz Felisiak
848fe70f3e
[3.2.x] Added CVE-2023-36053 to security archive.
...
Backport of 1d6fbf16f24200a556beb6dd197439944deb6837 from main
2023-07-03 10:31:45 +02:00
Mariusz Felisiak
4012a87a58
[3.2.x] Post-release version bump.
2023-07-03 08:36:12 +02:00
Mariusz Felisiak
19bc11f636
[3.2.x] Bumped version for 3.2.20 release.
3.2.20
2023-07-03 08:33:38 +02:00
Mariusz Felisiak
454f2fb934
[3.2.x] Fixed CVE-2023-36053 -- Prevented potential ReDoS in EmailValidator and URLValidator.
...
Thanks Seokchan Yoon for reports.
2023-07-03 08:32:26 +02:00
Mariusz Felisiak
07cc014cb3
[3.2.x] Added stub release notes for 3.2.20.
...
Backport of 2360ba22742c3ee8729697bfe2d508110465af56 from main
2023-06-26 14:39:49 +02:00
Mariusz Felisiak
e1bbbbe6ac
[3.2.x] Fixed MultipleFileFieldTest.test_file_multiple_validation() test if Pillow isn't installed.
...
Follow up to fb4c55d9ec4bb812a7fb91fa20510d91645e411b.
Backport of fcfbf08abe3e6dc54894df6988024f055abc6c40 from main
2023-05-04 08:10:11 +02:00
Mariusz Felisiak
47ef12e69c
[3.2.x] Added CVE-2023-31047 to security archive.
...
Backport of 49830025c992fbc8d8f213e7c16dba1391c6adf2 from main
2023-05-03 15:22:32 +02:00
Mariusz Felisiak
15f90ebff3
[3.2.x] Post-release version bump.
2023-05-03 14:00:58 +02:00
Mariusz Felisiak
fc42edd2e6
[3.2.x] Bumped version for 3.2.19 release.
3.2.19
2023-05-03 13:59:19 +02:00
Mariusz Felisiak
eed53d0011
[3.2.x] Fixed CVE-2023-31047, Fixed #31710 -- Prevented potential bypass of validation when uploading multiple files using one form field.
...
Thanks Moataz Al-Sharida and nawaik for reports.
Co-authored-by: Shai Berger <shai@platonix.com>
Co-authored-by: nessita <124304+nessita@users.noreply.github.com>
2023-05-03 13:58:52 +02:00
Mariusz Felisiak
007e46d815
[3.2.x] Added missing backticks in docs/releases/1.7.txt.
2023-04-26 09:37:36 +02:00
Mariusz Felisiak
a37e4d5d6e
[3.2.x] Added stub release notes for 3.2.19.
...
Backport of 18a7f2c711529f8e43c36190a5e2479f13899749 from main
2023-04-26 08:54:18 +02:00
Carlton Gibson
963f24cff2
[3.2.x] Added CVE-2023-24580 to security archive.
...
Backport of ecafcaf634fcef93f9da8cb12795273dd1c3a576 from main
2023-02-14 09:57:00 +01:00
Carlton Gibson
e34a2283f2
[3.2.x] Post-release version bump.
2023-02-14 09:07:53 +01:00
Carlton Gibson
722e9f8a38
[3.2.x] Bumped version for 3.2.18 release.
3.2.18
2023-02-14 09:04:22 +01:00
Markus Holtermann
a665ed5179
[3.2.x] Fixed CVE-2023-24580 -- Prevented DoS with too many uploaded files.
...
Thanks to Jakob Ackermann for the report.
2023-02-07 10:39:25 +01:00
Carlton Gibson
932b5bd52d
[3.2.x] Added stub release notes for 3.2.18.
...
Backport of 7e003428f96d616c1f77fed84882a95e63bc3644 from main
2023-02-07 10:14:53 +01:00
Mariusz Felisiak
c35a5788f4
[3.2.x] Added CVE-2023-23969 to security archive.
...
Backport of 36e3eef7d5a4c88671d20a561788679d0d9c334c from main
2023-02-01 12:11:00 +01:00
Mariusz Felisiak
9bd8db3940
[3.2.x] Post-release version bump.
2023-02-01 10:00:34 +01:00
Mariusz Felisiak
aed1bb56d1
[3.2.x] Bumped version for 3.2.17 release.
3.2.17
2023-02-01 09:58:36 +01:00
Nick Pope
c7e0151fdf
[3.2.x] Fixed CVE-2023-23969 -- Prevented DoS with pathological values for Accept-Language.
...
The parsed values of Accept-Language headers are cached in order to
avoid repetitive parsing. This leads to a potential denial-of-service
vector via excessive memory usage if the raw value of Accept-Language
headers is very large.
Accept-Language headers are now limited to a maximum length in order
to avoid this issue.
2023-02-01 09:48:18 +01:00
Mariusz Felisiak
9da46345d8
[3.2.x] Fixed inspectdb.tests.InspectDBTestCase.test_custom_fields() on SQLite 3.37+.
...
Use FlexibleFieldLookupDict which is case-insensitive mapping because
SQLite 3.37+ returns some data type names upper-cased e.g. TEXT.
Backport of 974e3b8750fe96c16c9c0b115a72ee4a2171df34 from main
2023-01-31 15:32:01 +01:00
Tim Graham
4c2b26174f
[3.2.x] Removed 'tests' path prefix in a couple tests.
...
Backport of 694cf458f16b8d340a3195244196980b2dec34fd from main.
2023-01-31 15:28:16 +01:00
Carlton Gibson
d21543182d
[3.2.x] Adjusted release notes for 3.2.17.
...
Backport of d8e1442ce2c56282785dd806e5c1147975e8c857 from main
2023-01-25 12:29:59 +01:00