1
0
mirror of https://github.com/django/django.git synced 2025-07-10 04:39:13 +00:00

4 Commits

Author SHA1 Message Date
Mariusz Felisiak
9f75e2e562 [3.2.x] Fixed CVE-2021-33571 -- Prevented leading zeros in IPv4 addresses.
validate_ipv4_address() was affected only on Python < 3.9.5, see [1].
URLValidator() uses a regular expressions and it was affected on all
Python versions.

[1] https://bugs.python.org/issue36384
2021-06-02 10:44:39 +02:00
Florian Apolloner
dfaba12cda [3.2.x] Fixed CVE-2021-33203 -- Fixed potential path-traversal via admindocs' TemplateDetailView. 2021-06-02 10:44:39 +02:00
Carlton Gibson
aed1409558 [3.2.x] Confirmed release date for Django 3.2.4, 3.1.12, and 2.2.24.
Backport of f66ae7a2d5558fe88ddfe639a610573872be6628 from main
2021-06-02 10:20:17 +02:00
Carlton Gibson
4ba4c07e4e [3.2.x] Added stub release notes and date for Django 3.2.4, 3.1.12, and 2.2.24.
Backport of b46dbd4e3e255223078ae0028934ea986e19ebc1 from main
2021-05-26 10:17:27 +02:00