mirror of
https://github.com/django/django.git
synced 2024-12-29 12:36:08 +00:00
fb4c55d9ec
Thanks Moataz Al-Sharida and nawaik for reports. Co-authored-by: Shai Berger <shai@platonix.com> Co-authored-by: nessita <124304+nessita@users.noreply.github.com>
24 lines
1.0 KiB
Plaintext
24 lines
1.0 KiB
Plaintext
==========================
|
|
Django 4.1.9 release notes
|
|
==========================
|
|
|
|
*May 3, 2023*
|
|
|
|
Django 4.1.9 fixes a security issue with severity "low" in 4.1.8.
|
|
|
|
CVE-2023-31047: Potential bypass of validation when uploading multiple files using one form field
|
|
=================================================================================================
|
|
|
|
Uploading multiple files using one form field has never been supported by
|
|
:class:`.forms.FileField` or :class:`.forms.ImageField` as only the last
|
|
uploaded file was validated. Unfortunately, :ref:`uploading_multiple_files`
|
|
topic suggested otherwise.
|
|
|
|
In order to avoid the vulnerability, :class:`~django.forms.ClearableFileInput`
|
|
and :class:`~django.forms.FileInput` form widgets now raise ``ValueError`` when
|
|
the ``multiple`` HTML attribute is set on them. To prevent the exception and
|
|
keep the old behavior, set ``allow_multiple_selected`` to ``True``.
|
|
|
|
For more details on using the new attribute and handling of multiple files
|
|
through a single field, see :ref:`uploading_multiple_files`.
|