summaryrefslogtreecommitdiff
path: root/docs/releases/3.2.11.txt
diff options
context:
space:
mode:
authorFlorian Apolloner <florian@apolloner.eu>2021-12-27 14:48:03 +0100
committerCarlton Gibson <carlton.gibson@noumenal.es>2022-01-04 10:02:05 +0100
commit968a3d01fa79f055f93a1c3ed1535ecbcbdbb842 (patch)
treeac977466ff6d3ae6daf70389f7895aad4c4e5981 /docs/releases/3.2.11.txt
parentccafad2e429468c518c80fb178f9e7a3f06e78e1 (diff)
Fixed CVE-2021-45115 -- Prevented DoS vector in UserAttributeSimilarityValidator.
Thanks Chris Bailey for the report. Co-authored-by: Adam Johnson <me@adamj.eu>
Diffstat (limited to 'docs/releases/3.2.11.txt')
-rw-r--r--docs/releases/3.2.11.txt14
1 files changed, 13 insertions, 1 deletions
diff --git a/docs/releases/3.2.11.txt b/docs/releases/3.2.11.txt
index b88f0f79ff..621139033c 100644
--- a/docs/releases/3.2.11.txt
+++ b/docs/releases/3.2.11.txt
@@ -7,4 +7,16 @@ Django 3.2.11 release notes
Django 3.2.11 fixes one security issue with severity "medium" and two security
issues with severity "low" in 3.2.10.
-...
+CVE-2021-45115: Denial-of-service possibility in ``UserAttributeSimilarityValidator``
+=====================================================================================
+
+:class:`.UserAttributeSimilarityValidator` incurred significant overhead
+evaluating submitted password that were artificially large in relative to the
+comparison values. On the assumption that access to user registration was
+unrestricted this provided a potential vector for a denial-of-service attack.
+
+In order to mitigate this issue, relatively long values are now ignored by
+``UserAttributeSimilarityValidator``.
+
+This issue has severity "medium" according to the :ref:`Django security policy
+<security-disclosure>`.