mirror of
https://github.com/django/django.git
synced 2025-10-09 06:49:12 +00:00
Migrated remaining response-related logging to use the `log_response()` helper to avoid potential log injection, to ensure untrusted values like request paths are safely escaped. Co-authored-by: Natalia <124304+nessita@users.noreply.github.com> Backport of 957951755259b412d5113333b32bf85871d29814 from main.
15 lines
411 B
Plaintext
15 lines
411 B
Plaintext
===========================
|
|
Django 4.2.23 release notes
|
|
===========================
|
|
|
|
*June 10, 2025*
|
|
|
|
Django 4.2.23 fixes a potential log injection issue in 4.2.22.
|
|
|
|
Bugfixes
|
|
========
|
|
|
|
* Fixed a log injection possibility by migrating remaining response logging
|
|
to ``django.utils.log.log_response()``, which safely escapes arguments such
|
|
as the request path to prevent unsafe log output (:cve:`2025-48432`).
|