diff options
| author | Carlton Gibson <carlton.gibson@noumenal.es> | 2022-08-03 09:09:48 +0200 |
|---|---|---|
| committer | Carlton Gibson <carlton.gibson@noumenal.es> | 2022-08-03 09:11:02 +0200 |
| commit | 777362d74aa3f3d88e6d60199f1d986200fb83b8 (patch) | |
| tree | a4c6bef2f603dd0166b507765677c527fa2c1a65 | |
| parent | eb5bdb461ea27b41d9d3d819fca062b3849556ee (diff) | |
[3.2.x] Added CVE-2022-36359 to security archive.
Backport of 57c7220280db19dc9dda0910b90cf1ceac50c66f from main
| -rw-r--r-- | docs/releases/security.txt | 10 |
1 files changed, 10 insertions, 0 deletions
diff --git a/docs/releases/security.txt b/docs/releases/security.txt index 2478287668..f039379e0e 100644 --- a/docs/releases/security.txt +++ b/docs/releases/security.txt @@ -36,6 +36,16 @@ Issues under Django's security process All security issues have been handled under versions of Django's security process. These are listed below. +August 3, 2022 - :cve:`2022-36359` +---------------------------------- + +Potential reflected file download vulnerability in FileResponse. `Full +description +<https://www.djangoproject.com/weblog/2022/aug/03/security-releases/>`__ + +* Django 4.0 :commit:`(patch) <b7d9529cbe0af4adabb6ea5d01ed8dcce3668fb3>` +* Django 3.2 :commit:`(patch) <b3e4494d759202a3b6bf247fd34455bf13be5b80>` + July 4, 2022 - :cve:`2022-34265` -------------------------------- |
