summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorCarlton Gibson <carlton.gibson@noumenal.es>2022-08-03 09:09:48 +0200
committerCarlton Gibson <carlton.gibson@noumenal.es>2022-08-03 09:10:23 +0200
commitc721b569a23bd4bacacd670531d7401e54118df4 (patch)
tree024fee07102d596ea5a1f535203ba63e02d355fe
parent46916665f9aa729067ef894e994854ecf9223157 (diff)
[4.1.x] Added CVE-2022-36359 to security archive.
Backport of 57c7220280db19dc9dda0910b90cf1ceac50c66f from main
-rw-r--r--docs/releases/security.txt10
1 files changed, 10 insertions, 0 deletions
diff --git a/docs/releases/security.txt b/docs/releases/security.txt
index 2478287668..f039379e0e 100644
--- a/docs/releases/security.txt
+++ b/docs/releases/security.txt
@@ -36,6 +36,16 @@ Issues under Django's security process
All security issues have been handled under versions of Django's security
process. These are listed below.
+August 3, 2022 - :cve:`2022-36359`
+----------------------------------
+
+Potential reflected file download vulnerability in FileResponse. `Full
+description
+<https://www.djangoproject.com/weblog/2022/aug/03/security-releases/>`__
+
+* Django 4.0 :commit:`(patch) <b7d9529cbe0af4adabb6ea5d01ed8dcce3668fb3>`
+* Django 3.2 :commit:`(patch) <b3e4494d759202a3b6bf247fd34455bf13be5b80>`
+
July 4, 2022 - :cve:`2022-34265`
--------------------------------