mirror of
				https://github.com/django/django.git
				synced 2025-10-31 01:25:32 +00:00 
			
		
		
		
	
		
			
				
	
	
		
			26 lines
		
	
	
		
			928 B
		
	
	
	
		
			Plaintext
		
	
	
	
	
	
			
		
		
	
	
			26 lines
		
	
	
		
			928 B
		
	
	
	
		
			Plaintext
		
	
	
	
	
	
| ==========================
 | |
| Django 2.1.6 release notes
 | |
| ==========================
 | |
| 
 | |
| *February 11, 2019*
 | |
| 
 | |
| Django 2.1.6 fixes a security issue and a bug in 2.1.5.
 | |
| 
 | |
| CVE-2019-6975: Memory exhaustion in ``django.utils.numberformat.format()``
 | |
| --------------------------------------------------------------------------
 | |
| 
 | |
| If ``django.utils.numberformat.format()`` -- used by ``contrib.admin`` as well
 | |
| as the ``floatformat``, ``filesizeformat``, and ``intcomma`` templates filters
 | |
| -- received a ``Decimal`` with a large number of digits or a large exponent, it
 | |
| could lead to significant memory usage due to a call to ``'{:f}'.format()``.
 | |
| 
 | |
| To avoid this, decimals with more than 200 digits are now formatted using
 | |
| scientific notation.
 | |
| 
 | |
| Bugfixes
 | |
| ========
 | |
| 
 | |
| * Made the ``obj`` argument of ``InlineModelAdmin.has_add_permission()``
 | |
|   optional to restore backwards compatibility with third-party code that
 | |
|   doesn't provide it (:ticket:`30097`).
 |