<feed xmlns='http://www.w3.org/2005/Atom'>
<title>django.git, branch 4.2.22</title>
<subtitle>django
</subtitle>
<id>http://cgit.adnoto.dev/django.git/atom?h=4.2.22</id>
<link rel='self' href='http://cgit.adnoto.dev/django.git/atom?h=4.2.22'/>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/django.git/'/>
<updated>2025-06-04T11:51:01Z</updated>
<entry>
<title>[4.2.x] Bumped version for 4.2.22 release.</title>
<updated>2025-06-04T11:51:01Z</updated>
<author>
<name>Natalia</name>
<email>124304+nessita@users.noreply.github.com</email>
</author>
<published>2025-06-04T11:51:01Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/django.git/commit/?id=7275cc5d1326fad562725ed47fbe5eb149dfa6fb'/>
<id>urn:sha1:7275cc5d1326fad562725ed47fbe5eb149dfa6fb</id>
<content type='text'>
</content>
</entry>
<entry>
<title>[4.2.x] Fixed CVE-2025-48432 -- Escaped formatting arguments in `log_response()`.</title>
<updated>2025-06-04T11:50:05Z</updated>
<author>
<name>Natalia</name>
<email>124304+nessita@users.noreply.github.com</email>
</author>
<published>2025-05-20T18:29:52Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/django.git/commit/?id=ac03c5e7df8680c61cdb0d3bdb8be9095dba841e'/>
<id>urn:sha1:ac03c5e7df8680c61cdb0d3bdb8be9095dba841e</id>
<content type='text'>
Suitably crafted requests containing a CRLF sequence in the request
path may have allowed log injection, potentially corrupting log files,
obscuring other attacks, misleading log post-processing tools, or
forging log entries.

To mitigate this, all positional formatting arguments passed to the
logger are now escaped using "unicode_escape" encoding.

Thanks to Seokchan Yoon (https://ch4n3.kr/) for the report.

Co-authored-by: Carlton Gibson &lt;carlton@noumenal.es&gt;
Co-authored-by: Jake Howard &lt;git@theorangeone.net&gt;

Backport of a07ebec5591e233d8bbb38b7d63f35c5479eef0e from main.
</content>
</entry>
<entry>
<title>[4.2.x] Added stub release notes and release date for 4.2.22.</title>
<updated>2025-05-28T13:21:44Z</updated>
<author>
<name>Natalia</name>
<email>124304+nessita@users.noreply.github.com</email>
</author>
<published>2025-05-28T13:03:06Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/django.git/commit/?id=c62f4eeda774b10541154b9e980f5b981030c4a0'/>
<id>urn:sha1:c62f4eeda774b10541154b9e980f5b981030c4a0</id>
<content type='text'>
Backport of 1a744343999c9646912cee76ba0a2fa6ef5e6240 from main.
</content>
</entry>
<entry>
<title>[4.2.x] Fixed #36402, Refs #35980 -- Updated built package name in reusable apps tutorial for PEP 625.</title>
<updated>2025-05-26T15:38:29Z</updated>
<author>
<name>Jason Judkins</name>
<email>34417573+jcjudkins@users.noreply.github.com</email>
</author>
<published>2025-05-26T15:33:29Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/django.git/commit/?id=c5b42632c95fdaaa46e2b9b512bf39346e21abc9'/>
<id>urn:sha1:c5b42632c95fdaaa46e2b9b512bf39346e21abc9</id>
<content type='text'>
Backport of 1307b8a1cb05762147736d0f347792b33f645390 from main.
</content>
</entry>
<entry>
<title>[4.2.x] Added helpers in csrf_tests and logging_tests to assert logs from `log_response()`.</title>
<updated>2025-05-22T18:45:13Z</updated>
<author>
<name>Natalia</name>
<email>124304+nessita@users.noreply.github.com</email>
</author>
<published>2025-05-20T01:46:00Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/django.git/commit/?id=32fd8dec5618bd09eccdeb9dbf512043193d68ef'/>
<id>urn:sha1:32fd8dec5618bd09eccdeb9dbf512043193d68ef</id>
<content type='text'>
Backport of ad6f99889838ccc2c30b3c02ed3868c9b565e81b from main.
</content>
</entry>
<entry>
<title>[4.2.x] Refs #26688 -- Added tests for `log_response()` internal helper.</title>
<updated>2025-05-22T18:44:44Z</updated>
<author>
<name>Natalia</name>
<email>124304+nessita@users.noreply.github.com</email>
</author>
<published>2025-05-20T01:45:38Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/django.git/commit/?id=acbe655a0fa1200d2de31c6020f310ba9aa2f636'/>
<id>urn:sha1:acbe655a0fa1200d2de31c6020f310ba9aa2f636</id>
<content type='text'>
Backport of 897046815944cc9a2da7ed9e8082f45ffe8110e3 from main.
</content>
</entry>
<entry>
<title>[4.2.x] Refs #35980 -- Added release note about changes in release artifacts filenames.</title>
<updated>2025-05-09T16:33:55Z</updated>
<author>
<name>Natalia</name>
<email>124304+nessita@users.noreply.github.com</email>
</author>
<published>2025-05-08T12:06:55Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/django.git/commit/?id=dc365cac9b48067d8fa75968fc2e9801293eecb2'/>
<id>urn:sha1:dc365cac9b48067d8fa75968fc2e9801293eecb2</id>
<content type='text'>
Backport of 42ab99309d347f617d60751c2e8d627fb2963049 from main.
</content>
</entry>
<entry>
<title>[4.2.x] Removed "Expected" from release date for 4.2.21.</title>
<updated>2025-05-09T16:33:08Z</updated>
<author>
<name>Natalia</name>
<email>124304+nessita@users.noreply.github.com</email>
</author>
<published>2025-05-08T11:50:02Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/django.git/commit/?id=c454afbf4c0461fd90f75391dc690b154abba6ef'/>
<id>urn:sha1:c454afbf4c0461fd90f75391dc690b154abba6ef</id>
<content type='text'>
Backport of c86156378db09e68db3a9ae1c108f661a67e3abe from main.
</content>
</entry>
<entry>
<title>[4.2.x] Cleaned up CVE-2025-32873 security archive description.</title>
<updated>2025-05-07T14:38:00Z</updated>
<author>
<name>Natalia</name>
<email>124304+nessita@users.noreply.github.com</email>
</author>
<published>2025-05-07T14:26:54Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/django.git/commit/?id=5b29315848450b7e7c5cdcd75096b1e172464330'/>
<id>urn:sha1:5b29315848450b7e7c5cdcd75096b1e172464330</id>
<content type='text'>
Backport of 37f2a77c729ccb71059c8e66c49b07499d2edf60 from main.
</content>
</entry>
<entry>
<title>[4.2.x] Added CVE-2025-32873 to security archive.</title>
<updated>2025-05-07T14:25:04Z</updated>
<author>
<name>Natalia</name>
<email>124304+nessita@users.noreply.github.com</email>
</author>
<published>2025-05-07T13:59:55Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/django.git/commit/?id=0d5495850a5e4f2aca6dc908d3db2248d96750b2'/>
<id>urn:sha1:0d5495850a5e4f2aca6dc908d3db2248d96750b2</id>
<content type='text'>
Backport of fdabda4e05587347aeb3382a442d7e77c1a0c3e5 from main.
</content>
</entry>
</feed>
