1
0
mirror of https://github.com/django/django.git synced 2025-06-02 10:09:12 +00:00

4892 Commits

Author SHA1 Message Date
Natalia
73f70b5cc8 [5.1.x] Cleaned up CVE-2025-32873 security archive description.
Backport of 37f2a77c729ccb71059c8e66c49b07499d2edf60 from main.
2025-05-07 11:37:34 -03:00
Natalia
05fab4e394 [5.1.x] Added CVE-2025-32873 to security archive.
Backport of fdabda4e05587347aeb3382a442d7e77c1a0c3e5 from main.
2025-05-07 11:09:35 -03:00
Sarah Boyce
0b42f6a528 [5.1.x] Fixed CVE-2025-32873 -- Mitigated potential DoS in strip_tags().
Thanks to Elias Myllymäki for the report, and Shai Berger and Jake
Howard for the reviews.

Co-authored-by: Natalia <124304+nessita@users.noreply.github.com>

Backport of 9f3419b519799d69f2aba70b9d25abe2e70d03e0 from main.
2025-05-06 22:31:16 -03:00
Natalia
1520d18e9c [5.1.x] Added upcoming security release to release notes.
Backport of 0f5dd0dff3049189a3fe71a62670b746543335d5 from main.
2025-04-30 14:56:53 -03:00
nessita
660067f8e7 [5.1.x] Refs #36341 -- Added release notes for 5.1.9 and 4.2.21 for fix in wordwrap template filter.
Revision 1e9db35836d42a3c72f3d1015c2f302eb6fee046 fixed a regression in
55d89e25f4115c5674cdd9b9bcba2bb2bb6d820b, which also needs to be
backported to the stable branches in extended support (5.1.x and 4.2.x).

Backport of c86242d61ff81bddbead115c458c1eb532d43b43 from main.
2025-04-23 17:30:05 -03:00
Sarah Boyce
39b144badd [5.1.x] Fixed #36298 -- Truncated the overwritten file content in file_move_safe().
Regression in 58cd4902a71a3695dd6c21dc957f59c333db364c.

Thanks Baptiste Mispelon for the report.

Backport of 8ad3e80e88201f4c557f6fa79fcfc0f8a0961830 from main.
2025-04-07 16:15:25 +02:00
Sarah Boyce
be13608613 [5.1.x] Added CVE-2025-27556 to security archive.
Backport of b83dab7d8da8d1dd888164de5ed79e88cedcb19b from main.
2025-04-02 13:33:19 +02:00
Sarah Boyce
edc2716d01 [5.1.x] Fixed CVE-2025-27556 -- Mitigated potential DoS in url_has_allowed_host_and_scheme() on Windows.
Thank you sw0rd1ight for the report.

Backport of 39e2297210d9d2938c75fc911d45f0e863dc4821 from main.
2025-04-02 10:28:26 +02:00
Sarah Boyce
451ba1f3cf [5.1.x] Added stub release notes and release date for 5.1.8 and 5.0.14.
Backport of c75fbe843079ca249d7015926490dd21107e63a4 from main.
2025-03-26 09:04:34 +01:00
Adam Johnson
cfc33d146e [5.1.x] Fixed #36234 -- Restored single_object argument to LogEntry.objects.log_actions().
Thank you Adam Johnson for the report and fix. Thank you Sarah Boyce for
your spot on analysis.

Regression in c09bceef68e5abb79accedd12dade16aa6577a09, which is
partially reverted in this branch.

Co-authored-by: Sarah Boyce <42296566+sarahboyce@users.noreply.github.com>

Backport of 27b68bcadf1ab2e9f7fd223aed42db352ccdc62d from main.
2025-03-12 16:39:14 -03:00
Sarah Boyce
74d41970af [5.1.x] Added CVE-2025-26699 to security archive.
Backport of bad1a18ff28a671f2fdfd447bdf8f43602f882c2 from main.
2025-03-06 14:07:09 +01:00
Sarah Boyce
4b2ddd015a [5.1.x] Added stub release notes for 5.1.8.
Backport of 193e3446e38c5415465608f68620508eace60388 from main.
2025-03-06 13:33:23 +01:00
Sarah Boyce
8dbb44d342 [5.1.x] Fixed CVE-2025-26699 -- Mitigated potential DoS in wordwrap template filter.
Thanks sw0rd1ight for the report.

Backport of 55d89e25f4115c5674cdd9b9bcba2bb2bb6d820b from main.
2025-03-06 09:42:06 +01:00
antoliny0919
03ace756ea [5.1.x] Fixed #36217 -- Restored pre_save/post_save signal emission via LogEntry.save() for single-object deletion in the admin.
Regression in 40b3975e7d3e1464a733c69171ad7d38f8814280.

Thanks smiling-watermelon for the report.

Co-authored-by: Sarah Boyce <42296566+sarahboyce@users.noreply.github.com>

Backport of c09bceef68e5abb79accedd12dade16aa6577a09 from main.
2025-03-04 10:38:15 +01:00
Sarah Boyce
558c616c95 [5.1.x] Added stub release notes and release date for 5.1.7, 5.0.13, and 4.2.20.
Backport of ea1e3703bee28bfbe4f32ceb39ad31763353b143 from main.
2025-02-27 16:08:13 +01:00
Simon Charette
8488074fe3 [5.1.x] Fixed #36197 -- Fixed improper many-to-many count() and exists() for non-pk to_field.
Regression in 66e47ac69a7e71cf32eee312d05668d8f1ba24bb.

Thanks mfontana-elem for the report and Sarah for the tests.

Backport of c3a23aa02faa1cf1d32e43d66858e793cd9ecac4 from main.
2025-02-18 11:45:45 +01:00
Gaël Utard
a9d03c4094 [5.1.x] Fixed #36191 -- Truncated the overwritten file content in FileSystemStorage.
Backport of 0d1dd6bba0c18b7feb6caa5cbd8df80fbac54afd from main.
2025-02-17 14:06:03 +01:00
Sarah Boyce
65113401f1 [5.1.x] Fixed #36182 -- Returned "?" if all parameters are removed in querystring template tag.
Thank you to David Feeley for the report and Natalia Bidart for the review.

Backport of 05002c153c5018e4429a326a6699c7c45e5ea957 from main.
2025-02-13 15:57:56 +01:00
Natalia
e7a9d20380 [5.1.x] Added stub release notes for 5.1.7.
Backport of e2a8f4dac8ed2b3667a4367756043b1e119f4ce2 from main.
2025-02-05 11:21:56 -03:00
Natalia
df27e43234 [5.1.x] Added release date for 5.1.6, 5.0.12, and 4.2.19.
Backport of 294cc965efe0dfc8457aa5a8e78cb6d53abfcf92 from main.
2025-02-05 10:40:13 -03:00
nessita
8552eef95e [5.1.x] Fixed #36140 -- Allowed BaseUserCreationForm to define non required password fields.
Regression in e626716c28b6286f8cf0f8174077f3d2244f3eb3.

Thanks buffgecko12 for the report and Sarah Boyce for the review.

Backport of d15454a6e84a595ffc8dc1b926282f484f782a8f from main.
2025-02-01 22:51:06 -03:00
nessita
4f0169e94f [5.1.x] Tweaked docs to avoid reformatting given new black version.
Backport of fd3cfd80bebad292d639a03e58632e494369eb92 from main.
2025-01-30 10:39:08 -03:00
Mariusz Felisiak
c81669cb54 [5.1.x] Fixed #36098 -- Fixed validate_ipv6_address()/validate_ipv46_address() crash for non-string values.
Regression in ca2be7724e1244a4cb723de40a070f873c6e94bf.

Backport of b3c5830769d8a5dbf2f974da7116fe503c9454d9 from main.
2025-01-15 13:47:13 -03:00
Natalia
dd2247d5fd [5.1.x] Added CVE-2024-56374 to security archive.
Backport of f2a1dcaa53626ff11b921ef142b780a8fd746d32 from main.
2025-01-14 11:39:03 -03:00
Natalia
7b8fca716d [5.1.x] Added stub release notes for 5.1.6.
Backport of 3b46bea90933b8fb24f4ddfa8a3943032a5a370e from main.
2025-01-14 11:34:16 -03:00
Michael Manfre
4806731e58 [5.1.x] Fixed CVE-2024-56374 -- Mitigated potential DoS in IPv6 validation.
Thanks Saravana Kumar for the report, and Sarah Boyce and Mariusz
Felisiak for the reviews.

Co-authored-by: Natalia <124304+nessita@users.noreply.github.com>
2025-01-14 08:44:20 -03:00
Natalia
d6749de927 [5.1.x] Made cosmetic edits to 5.1.5 release notes.
Backport of 9a2dd9789a2edeed7344a8ec0d17142ad27443a1 from main.
2025-01-14 08:34:40 -03:00
Natalia
0966cc7364 [5.1.x] Added stub release notes and release date for 5.1.5, 5.0.11, and 4.2.18.
Backport of 53e21eebf22bc05c7fa30820b453b7f345b7af40 from main.
2025-01-07 12:32:08 -03:00
Andrés Reverón Molina
2ee6ca6d35 [5.1.x] Fixed #34856 -- Fixed references to index_together in historical migrations.
While AlterUniqueTogether has been documented to be still allowed in historical
migrations for the foreseeable future it has been crashing since 2abf417c815c20
was merged because the latter removed support for Meta.index_together which the
migration framework uses to render models to perform schema changes.

CreateModel(options["unique_together"]) was also affected.

Refs #27236.

Co-authored-by: Simon Charette <charette.s@gmail.com>

Backport of b44efdfe543c9b9f12690b59777e6b275cb08103 from main.
2024-12-17 10:01:51 +01:00
Sarah Boyce
65e8c8f776 [5.1.x] Cleaned up CVE-2024-53907 and CVE-2024-53908 security archive descriptions.
Backport of eb665e076ca3417eb0ac654aed9e9c1853c5af84 from main.
2024-12-04 17:01:12 +01:00
Sarah Boyce
d972812d82 [5.1.x] Added CVE-2024-53907 and CVE-2024-53908 to security archive.
Backport of 595cb4a7aeb1ba1770d10d601ce9a2b4e487c46e from main.
2024-12-04 16:31:03 +01:00
Sarah Boyce
22dca34036 [5.1.x] Added stub release notes for 5.1.5.
Backport of 828afd782f8bc019401075bd51fad039cc5ceff0 from main.
2024-12-04 16:25:26 +01:00
Simon Charette
6943d61818 [5.1.x] Fixed CVE-2024-53908 -- Prevented SQL injections in direct HasKeyLookup usage on Oracle.
Thanks Seokchan Yoon for the report, and Mariusz Felisiak and Sarah
Boyce for the reviews.
2024-12-04 13:47:31 +01:00
Sarah Boyce
bbc74a7f7e [5.1.x] Fixed CVE-2024-53907 -- Mitigated potential DoS in strip_tags().
Thanks to jiangniao for the report, and Shai Berger and Natalia Bidart
for the reviews.
2024-12-04 13:47:21 +01:00
Adam Johnson
6e3e7353e0 [5.1.x] Fixed #35950 -- Restored refreshing of relations when fields deferred.
Thank you to Simon Charette and Sarah Boyce for the review.

Regression in 73df8b54a2fab53bec4c7573cda5ad8c869c2fd8.

Backport of 2f6b096b83c55317c7ceef2d8d5dc3bee33293dc from main.
2024-12-02 16:05:11 +01:00
Sarah Boyce
5f82a5e4c7 [5.1.x] Added stub release notes and release date for 5.1.4, 5.0.10, and 4.2.17.
Backport of 2544c1585473c1e82dab1274b52052744f97ca72 from main.
2024-11-27 15:42:58 +01:00
Tommy Allen
4b262408aa [5.1.x] Fixed #35942 -- Fixed createsuperuser crash on Python 3.13+ when username is unavailable.
Thanks Mariusz Felisiak and Jacob Tyler Walls for reviews.

Backport of c635decb00ac957daf81c08541cdc9cf46f6d86d from main.
2024-11-26 17:16:30 -03:00
Mariusz Felisiak
a0d8fad23e [5.1.x] Added stub release notes for 5.1.4.
Backport of 2d41e40ddfe90de4bc1ceeba38bbe1f6eb4ce7ce from main
2024-11-05 06:32:04 +01:00
Mariusz Felisiak
e3984ca5d1 [5.1.x] Added release date for 5.1.3.
Backport of ecd81ac8b786ac6f4e8a5626e0d029bcb11064a5 from main
2024-11-05 05:56:39 +01:00
Sarah Boyce
9fa2d235c9 [5.1.x] Fixed #35876 -- Displayed non-ASCII fieldset names when rendering ModelAdmin.fieldsets.
Thank you to Namhong Kim for the report, and to Mariusz Felisiak and Marijke Luttekes for the review.

Regression in 01ed59f753139afb514170ee7f7384c155ecbc2d.

Backport of 2c029c718f45341cdd43ee094c24488743c633e6 from main.
2024-10-31 06:41:10 +01:00
Nick Pope
51eb666758 [5.1.x] Fixed #35841 -- Restored support for DB-IP databases in GeoIP2.
Thanks Felix Farquharson for the report and Claude Paroz for the
review.

Regression in 40b5b1596f7505416bd30d5d7582b5a9004ea7d5.

Co-authored-by: Natalia <124304+nessita@users.noreply.github.com>

Backport of 3fad712a91a8a8f6f6f904aff3d895e3b06b24c7 from main.
2024-10-17 21:42:06 -03:00
Justin Thurman
3ba8b0dae8 [5.1.x] Fixed #35845 -- Updated DomainNameValidator to require entire string to be a valid domain name.
Bug in 4971a9afe5642569f3dcfcd3972ebb39e88dd457.

Thank you to kazet for the report and Claude Paroz for the review.

Backport of 99dcc59237f384d7ade98acfd1cae8d90e6d60ab from main.
2024-10-17 17:00:35 +02:00
Mariusz Felisiak
e2551b30ad [5.1.x] Refs #34900 -- Doc'd Python 3.13 compatibility.
Backport of 2e3bc59fd3760de87952ec8fd6cd3694e8d9dc1c from main.
2024-10-09 09:56:42 +02:00
Natalia
52f2996b9b [5.1.x] Added stub release notes for 5.1.3.
Backport of 4d11402932eca570850bdfa58a71eb59fc62275a from main.
2024-10-08 12:04:53 -03:00
Natalia
6e07a7769f [5.1.x] Added release date for 5.1.2.
Backport of 5bb433e99bc24625295e05448fdf173dc72028ad from main.
2024-10-08 11:39:02 -03:00
nessita
17fa7592af [5.1.x] Fixed #35809 -- Set background color for selected rows in the admin's form select widget.
Regression in b47bdb4cd9149ee2a39bf1cc9996a36a940bd7d9.

Thank you Giannis Terzopoulos for the review, and Tom Carrick and Sarah Boyce
for the review.

Backport of 679d57816d716cbc7cff3b364ae265d70444ebd9 from main.
2024-10-08 10:02:33 -03:00
nessita
e245f62d00
[5.1.x] Updated translations from Transifex. 2024-10-07 17:35:43 -03:00
John Parton
22bce642a9 [5.1.x] Fixed #35734 -- Used JSONB_BUILD_OBJECT database function on PostgreSQL when using server-side bindings.
Regression in 81ccf92f154c6d9eac3e30bac0aa67574d0ace15.

Backport of f22ff4561ada77be98ca4db3ce117caca897696e from main.
2024-09-26 16:22:59 +02:00
Gastón Avila
590f5e09f0 [5.1.x] Fixed #35732 -- Wrapped ConcatPair expression in parentheses to ensure operator precedence.
When ConcatPair was updated to use || this lost the implicit wrapping from CONCAT(...).
This broke the WHERE clauses when used in combination with PostgreSQL trigram similarity.

Regression in 6364b6ee1071381eb3a23ba6b821fc0d6f0fce75.

Backport of c3ca6075cc0ad425bcf905fe14062f38eb9fbcbf from main.

Co-authored-by: Emiliano Cuenca <106986074+emicuencac@users.noreply.github.com>
2024-09-11 14:40:48 +02:00
Natalia
1b7b5e0d17 [5.1.x] Added CVE-2024-45230 and CVE-2024-45231 to security archive.
Backport of aa5293068782dfa2d2173c75c8477f58a9989942 from main.
2024-09-03 11:24:09 -03:00