Mariusz Felisiak
f9a7fb8466
[3.2.x] Fixed CVE-2023-46695 -- Fixed potential DoS in UsernameField on Windows.
...
Thanks MProgrammer (https://hackerone.com/mprogrammer ) for the report.
2023-11-01 06:30:59 +01:00
Mariusz Felisiak
e6d2591d9e
[3.2.x] Added stub release notes for 3.2.23.
...
Backport of fdd1323b9c83e56184e0c992af8faf8d54327775 from main.
2023-10-25 05:47:09 +02:00
Natalia
3c04b74293
[3.2.x] Added CVE-2023-43665 to security archive.
...
Backport of 4e790271e3e65c9ad037b347a34fa95e11982228 from main
2023-10-04 13:11:42 -03:00
Natalia
ccdade1a02
[3.2.x] Fixed CVE-2023-43665 -- Mitigated potential DoS in django.utils.text.Truncator when truncating HTML text.
...
Thanks Wenchao Li of Alibaba Group for the report.
2023-10-04 09:41:12 -03:00
Natalia
6caf7b313d
[3.2.x] Added stub release notes for 3.2.22.
...
Backport of 24f1a38b37c0af3a5ce0dd7b5392fe4e75d7e1dc from main.
2023-09-27 14:34:57 -03:00
Mariusz Felisiak
9e814c3a5e
[3.2.x] Added CVE-2023-41164 to security archive.
...
Backport of 8a98768868a104ea3ce10d8182590bdd095d9ccb from main
2023-09-04 13:18:49 +02:00
Mariusz Felisiak
6f030b1149
[3.2.x] Fixed CVE-2023-41164 -- Fixed potential DoS in django.utils.encoding.uri_to_iri().
...
Thanks MProgrammer (https://hackerone.com/mprogrammer ) for the report.
Co-authored-by: nessita <124304+nessita@users.noreply.github.com>
2023-09-04 12:23:18 +02:00
Mariusz Felisiak
73350a6369
[3.2.x] Added stub release notes for 3.2.21.
...
Backport of 24f1a38b37c0af3a5ce0dd7b5392fe4e75d7e1dc from main.
2023-08-28 06:19:18 +02:00
David Smith
75418f8c0e
[3.2.x] Fixed #34756 -- Fixed docs HTML build on Sphinx 7.1+.
...
Backport of b3e0170ab546a96930ce3114b0a1a560953c0ff4 from main
2023-08-03 09:38:10 +02:00
Mariusz Felisiak
848fe70f3e
[3.2.x] Added CVE-2023-36053 to security archive.
...
Backport of 1d6fbf16f24200a556beb6dd197439944deb6837 from main
2023-07-03 10:31:45 +02:00
Mariusz Felisiak
454f2fb934
[3.2.x] Fixed CVE-2023-36053 -- Prevented potential ReDoS in EmailValidator and URLValidator.
...
Thanks Seokchan Yoon for reports.
2023-07-03 08:32:26 +02:00
Mariusz Felisiak
07cc014cb3
[3.2.x] Added stub release notes for 3.2.20.
...
Backport of 2360ba22742c3ee8729697bfe2d508110465af56 from main
2023-06-26 14:39:49 +02:00
Mariusz Felisiak
47ef12e69c
[3.2.x] Added CVE-2023-31047 to security archive.
...
Backport of 49830025c992fbc8d8f213e7c16dba1391c6adf2 from main
2023-05-03 15:22:32 +02:00
Mariusz Felisiak
eed53d0011
[3.2.x] Fixed CVE-2023-31047, Fixed #31710 -- Prevented potential bypass of validation when uploading multiple files using one form field.
...
Thanks Moataz Al-Sharida and nawaik for reports.
Co-authored-by: Shai Berger <shai@platonix.com>
Co-authored-by: nessita <124304+nessita@users.noreply.github.com>
2023-05-03 13:58:52 +02:00
Mariusz Felisiak
007e46d815
[3.2.x] Added missing backticks in docs/releases/1.7.txt.
2023-04-26 09:37:36 +02:00
Mariusz Felisiak
a37e4d5d6e
[3.2.x] Added stub release notes for 3.2.19.
...
Backport of 18a7f2c711529f8e43c36190a5e2479f13899749 from main
2023-04-26 08:54:18 +02:00
Carlton Gibson
963f24cff2
[3.2.x] Added CVE-2023-24580 to security archive.
...
Backport of ecafcaf634fcef93f9da8cb12795273dd1c3a576 from main
2023-02-14 09:57:00 +01:00
Markus Holtermann
a665ed5179
[3.2.x] Fixed CVE-2023-24580 -- Prevented DoS with too many uploaded files.
...
Thanks to Jakob Ackermann for the report.
2023-02-07 10:39:25 +01:00
Carlton Gibson
932b5bd52d
[3.2.x] Added stub release notes for 3.2.18.
...
Backport of 7e003428f96d616c1f77fed84882a95e63bc3644 from main
2023-02-07 10:14:53 +01:00
Mariusz Felisiak
c35a5788f4
[3.2.x] Added CVE-2023-23969 to security archive.
...
Backport of 36e3eef7d5a4c88671d20a561788679d0d9c334c from main
2023-02-01 12:11:00 +01:00
Nick Pope
c7e0151fdf
[3.2.x] Fixed CVE-2023-23969 -- Prevented DoS with pathological values for Accept-Language.
...
The parsed values of Accept-Language headers are cached in order to
avoid repetitive parsing. This leads to a potential denial-of-service
vector via excessive memory usage if the raw value of Accept-Language
headers is very large.
Accept-Language headers are now limited to a maximum length in order
to avoid this issue.
2023-02-01 09:48:18 +01:00
Carlton Gibson
d21543182d
[3.2.x] Adjusted release notes for 3.2.17.
...
Backport of d8e1442ce2c56282785dd806e5c1147975e8c857 from main
2023-01-25 12:29:59 +01:00
Carlton Gibson
4e31d3ea55
[3.2.x] Added stub release notes for 3.2.17.
...
Backport of 1df963ad2476726d63be132c0cee47e07b8250d7 from main
2023-01-25 12:02:29 +01:00
Mariusz Felisiak
b381ab4906
[3.2.x] Disabled auto-created table of contents entries on Sphinx 5.2+.
...
Auto-created table of contents entries for all domain objects (e.g.
functions, classes, attributes, etc.) were added in Sphinx 5.2, see
https://github.com/sphinx-doc/sphinx/issues/6316 .
An option to control new table of contents entries was added in Sphinx
5.2.3, see https://github.com/sphinx-doc/sphinx/pull/10886 .
Backport of 279967ec859a9a5240318cf29a077539b0e3139f from main
2022-12-29 06:15:37 +01:00
Nick Pope
f6f0699d01
[3.2.x] Removed obsolete doc reference to asyncio.iscoroutinefunction.
...
Backport of 970f61fefb148284fb2af63b5cc844279254111a from main
2022-10-29 13:36:23 +02:00
Carlton Gibson
accdd0576d
[3.2.x] Added CVE-2022-36359 to security archive.
...
Backport of 93d4c9ea1de24eb391cb2b3561b6703fd46374df from main
2022-10-04 10:13:25 +02:00
Adam Johnson
5b6b257fa7
[3.2.x] Fixed CVE-2022-41323 -- Prevented locales being interpreted as regular expressions.
...
Thanks to Benjamin Balder Bach for the report.
2022-09-27 10:17:34 +02:00
Carlton Gibson
33affaf0b6
[3.2.x] Added stub notes 3.2.16 release.
...
Backport of 57c7220280db19dc9dda0910b90cf1ceac50c66f from main
2022-09-27 10:14:45 +02:00
Carlton Gibson
777362d74a
[3.2.x] Added CVE-2022-36359 to security archive.
...
Backport of 57c7220280db19dc9dda0910b90cf1ceac50c66f from main
2022-08-03 09:11:02 +02:00
Carlton Gibson
b3e4494d75
[3.2.x] Fixed CVE-2022-36359 -- Escaped filename in Content-Disposition header.
...
Thanks to Motoyasu Saburi for the report.
2022-08-03 08:48:33 +02:00
Carlton Gibson
a5eba20f40
Adjusted release notes for 3.2.15.
...
Backport of cadd864f6878c1c02a014589876ece166befdeb3 from main
2022-07-27 10:05:04 +02:00
Carlton Gibson
ad104fb50f
[3.2.x] Added stub release notes for 3.2.15 release.
...
Backport of 0c1675781ec5944132fe5a475ca6064edc71bd81 from main
2022-07-27 09:34:30 +02:00
Mariusz Felisiak
e1cfbe58b7
[3.2.x] Added CVE-2022-34265 to security archive.
...
Backport of d12d7c4c42814736c24731a6a300a79526fc2ef6 from main
2022-07-04 10:34:52 +02:00
Mariusz Felisiak
a9010fe555
[3.2.x] Fixed CVE-2022-34265 -- Protected Trunc(kind)/Extract(lookup_name) against SQL injection.
...
Thanks Takuto Yoshikai (Aeye Security Lab) for the report.
2022-07-04 08:41:33 +02:00
Mariusz Felisiak
4a5d98ee0a
[3.2.x] Bumped minimum Sphinx version to 4.5.0.
...
Related Sphinx changes:
- https://github.com/sphinx-doc/sphinx/pull/8898
- https://github.com/sphinx-doc/sphinx/issues/8326
Backport of ebf25555bbed3e9112d4b726575d60b242daf48a from main.
2022-06-27 08:45:07 +02:00
Mariusz Felisiak
1a9098166e
[3.2.x] Fixed docs build with sphinxcontrib-spelling 7.5.0+.
...
sphinxcontrib-spelling 7.5.0+ includes captions of figures in the set
of nodes for which the text is checked.
Backport of ac90529cc58507d9a07610809a795ec5fc3cbf8c from main.
2022-06-27 08:10:48 +02:00
Mariusz Felisiak
37f4de2deb
[3.2.x] Added stub release notes for 3.2.14.
...
Backport of b2eff16806057095c7dd3daa9402ad615e51627f from main
2022-06-27 07:23:46 +02:00
Mariusz Felisiak
a23c25d84a
[3.2.x] Fixed #33753 -- Fixed docs build on Sphinx 5+.
...
Empty language is not supported anymore.
Backport of 565ad5ace46aa1e2368450701cba45dd1a95a026 from main
2022-06-01 12:15:27 +02:00
Mariusz Felisiak
e01b383e02
[3.2.x] Added CVE-2022-28346 and CVE-2022-28347 to security archive.
...
Backport of 78eeff8d33ead67cfc8603477c95e70f8fbe096a from main
2022-04-11 10:36:52 +02:00
Mariusz Felisiak
9e19accb6e
[3.2.x] Fixed CVE-2022-28347 -- Protected QuerySet.explain(**options) against SQL injection on PostgreSQL.
...
Backport of 6723a26e59b0b5429a0c5873941e01a2e1bdbb81 from main.
2022-04-11 09:12:58 +02:00
Mariusz Felisiak
2044dac5c6
[3.2.x] Fixed CVE-2022-28346 -- Protected QuerySet.annotate(), aggregate(), and extra() against SQL injection in column aliases.
...
Thanks Splunk team: Preston Elder, Jacob Davis, Jacob Moore,
Matt Hanson, David Briggs, and a security researcher: Danylo Dmytriiev
(DDV_UA) for the report.
Backport of 93cae5cb2f9a4ef1514cf1a41f714fef08005200 from main.
2022-04-11 09:12:06 +02:00
Manel Clos
bdb92dba0b
[3.2.x] Fixed #33628 -- Ignored directories with empty names in autoreloader check for template changes.
...
Regression in 68357b2ca9e88c40fc00d848799813241be39129.
Backport of 62739b6e2630e37faa68a86a59fad135cc788cd7 from main.
2022-04-11 08:34:01 +02:00
Mariusz Felisiak
70035fb044
[3.2.x] Added stub release notes for 3.2.13 and 2.2.28.
...
Backport of 78277faafd38d8360efc1fd0c9c52d7bb5eec002 from main
2022-04-04 10:51:06 +02:00
David Smith
754af45773
[3.2.x] Fixed typo in release notes.
...
Backport of 770d3e6a4ce8e0a91a9e27156036c1985e74d4a3 from main.
2022-02-02 07:19:30 +01:00
Mariusz Felisiak
6f309165e5
[3.2.x] Added CVE-2022-22818 and CVE-2022-23833 to security archive.
...
Backport of 9e0df0d6dde441dbbad2b548d777e0a01d633286 from main
2022-02-01 08:53:32 +01:00
Mariusz Felisiak
d16133568e
[3.2.x] Fixed CVE-2022-23833 -- Fixed DoS possiblity in file uploads.
...
Thanks Alan Ryan for the report and initial patch.
Backport of fc18f36c4ab94399366ca2f2007b3692559a6f23 from main.
2022-02-01 07:54:17 +01:00
Markus Holtermann
1a1e8278c4
[3.2.x] Fixed CVE-2022-22818 -- Fixed possible XSS via {% debug %} template tag.
...
Thanks Keryn Knight for the report.
Backport of 394517f07886495efcf79f95c7ee402a9437bd68 from main.
Co-authored-by: Adam Johnson <me@adamj.eu>
2022-02-01 07:53:21 +01:00
Mariusz Felisiak
a7e89fe776
[3.2.x] Added stub release notes for 3.2.12 and 2.2.27.
...
Backport of eeca9342381c8583be16f18942774e785ab7e527 from main.
2022-01-25 07:27:35 +01:00
Carlton Gibson
027f4c4ceb
[3.2.x] Added CVE-2021-45115, CVE-2021-45116, and CVE-2021-45452 to security archive.
...
Backport of 63869ab1f191ab5781cde8b813b838300455f6d6 from main
2022-01-04 11:31:13 +01:00
Florian Apolloner
8d2f7cff76
[3.2.x] Fixed CVE-2021-45452 -- Fixed potential path traversal in storage subsystem.
...
Thanks to Dennis Brinkrolf for the report.
2022-01-04 10:19:49 +01:00