diff options
| author | Carlton Gibson <carlton.gibson@noumenal.es> | 2021-05-04 11:06:07 +0200 |
|---|---|---|
| committer | Carlton Gibson <carlton.gibson@noumenal.es> | 2021-05-04 11:10:50 +0200 |
| commit | df801dde3344549bcd8db2abe6b0e4ac23f278ca (patch) | |
| tree | d4e81cd11198336fe7a54c141fea02a23c54394e | |
| parent | 04d8ed3660c6375c75e106ac73b3faf3d11f11e8 (diff) | |
[3.2.x] Added CVE-2021-31542 to security archive.
Backport of 607ebbfba915de2d84eb943aa93654f31817a709 and
62b2e8b37e37a313c63be40e3223ca4e830ebde3 from main
| -rw-r--r-- | docs/releases/security.txt | 13 |
1 files changed, 13 insertions, 0 deletions
diff --git a/docs/releases/security.txt b/docs/releases/security.txt index 6baebb21f5..847abd9cac 100644 --- a/docs/releases/security.txt +++ b/docs/releases/security.txt @@ -36,6 +36,19 @@ Issues under Django's security process All security issues have been handled under versions of Django's security process. These are listed below. +May 4, 2021 - :cve:`2021-31542` +------------------------------- + +Potential directory-traversal via uploaded files. `Full description +<https://www.djangoproject.com/weblog/2021/may/04/security-releases/>`__ + +Versions affected +~~~~~~~~~~~~~~~~~ + +* Django 3.2 :commit:`(patch) <c98f446c188596d4ba6de71d1b77b4a6c5c2a007>` +* Django 3.1 :commit:`(patch) <25d84d64122c15050a0ee739e859f22ddab5ac48>` +* Django 2.2 :commit:`(patch) <04ac1624bdc2fa737188401757cf95ced122d26d>` + April 6, 2021 - :cve:`2021-28658` --------------------------------- |
