Mariusz Felisiak
203d4ab9eb
[3.1.x] Fixed CVE-2021-33571 -- Prevented leading zeros in IPv4 addresses.
...
validate_ipv4_address() was affected only on Python < 3.9.5, see [1].
URLValidator() uses a regular expressions and it was affected on all
Python versions.
[1] https://bugs.python.org/issue36384
2021-06-02 10:38:07 +02:00
Florian Apolloner
20c67a0693
[3.1.x] Fixed CVE-2021-33203 -- Fixed potential path-traversal via admindocs' TemplateDetailView.
2021-06-02 10:38:07 +02:00
Carlton Gibson
aa8781c0a6
[3.1.x] Confirmed release date for Django 3.1.12, and 2.2.24.
...
Backport of f66ae7a2d5558fe88ddfe639a610573872be6628 from main
2021-06-02 10:22:02 +02:00
Carlton Gibson
c7fdc790cf
[3.1.x] Added stub release notes and date for Django 3.1.12 and 2.2.24.
...
Backport of b46dbd4e3e255223078ae0028934ea986e19ebc1 from main
2021-05-26 10:19:28 +02:00