mirror of
				https://github.com/django/django.git
				synced 2025-10-31 01:25:32 +00:00 
			
		
		
		
	
		
			
				
	
	
		
			17 lines
		
	
	
		
			640 B
		
	
	
	
		
			Plaintext
		
	
	
	
	
	
			
		
		
	
	
			17 lines
		
	
	
		
			640 B
		
	
	
	
		
			Plaintext
		
	
	
	
	
	
| ===========================
 | |
| Django 2.2.19 release notes
 | |
| ===========================
 | |
| 
 | |
| *February 19, 2021*
 | |
| 
 | |
| Django 2.2.19 fixes a security issue in 2.2.18.
 | |
| 
 | |
| CVE-2021-23336: Web cache poisoning via ``django.utils.http.limited_parse_qsl()``
 | |
| =================================================================================
 | |
| 
 | |
| Django contains a copy of :func:`urllib.parse.parse_qsl` which was added to
 | |
| backport some security fixes. A further security fix has been issued recently
 | |
| such that ``parse_qsl()`` no longer allows using ``;`` as a query parameter
 | |
| separator by default. Django now includes this fix. See :bpo:`42967` for
 | |
| further details.
 |