mirror of
				https://github.com/django/django.git
				synced 2025-10-31 01:25:32 +00:00 
			
		
		
		
	
		
			
				
	
	
		
			33 lines
		
	
	
		
			1.2 KiB
		
	
	
	
		
			Plaintext
		
	
	
	
	
	
			
		
		
	
	
			33 lines
		
	
	
		
			1.2 KiB
		
	
	
	
		
			Plaintext
		
	
	
	
	
	
| ===========================
 | |
| Django 2.0.10 release notes
 | |
| ===========================
 | |
| 
 | |
| *January 4, 2019*
 | |
| 
 | |
| Django 2.0.10 fixes a security issue and several bugs in 2.0.9.
 | |
| 
 | |
| CVE-2019-3498: Content spoofing possibility in the default 404 page
 | |
| -------------------------------------------------------------------
 | |
| 
 | |
| An attacker could craft a malicious URL that could make spoofed content appear
 | |
| on the default page generated by the ``django.views.defaults.page_not_found()``
 | |
| view.
 | |
| 
 | |
| The URL path is no longer displayed in the default 404 template and the
 | |
| ``request_path`` context variable is now quoted to fix the issue for custom
 | |
| templates that use the path.
 | |
| 
 | |
| Bugfixes
 | |
| ========
 | |
| 
 | |
| * Prevented repetitive calls to ``geos_version_tuple()`` in the ``WKBWriter``
 | |
|   class in an attempt to fix a random crash involving ``LooseVersion`` since
 | |
|   Django 2.0.6 (:ticket:`29959`).
 | |
| 
 | |
| * Fixed a schema corruption issue on SQLite 3.26+. You might have to drop and
 | |
|   rebuild your SQLite database if you applied a migration while using an older
 | |
|   version of Django with SQLite 3.26 or later (:ticket:`29182`).
 | |
| 
 | |
| * Prevented SQLite schema alterations while foreign key checks are enabled to
 | |
|   avoid the possibility of schema corruption (:ticket:`30023`).
 |