summaryrefslogtreecommitdiff
path: root/docs/releases
diff options
context:
space:
mode:
authorCarlton Gibson <carlton.gibson@noumenal.es>2019-12-02 11:42:24 +0100
committerCarlton Gibson <carlton.gibson@noumenal.es>2019-12-02 11:42:24 +0100
commit900ea762e5d1342e84a645483d05b90e6d908f2d (patch)
tree0fd53f4f8013ec8c51a2b8cfb53e5dfda49034f3 /docs/releases
parent6376278a904e2f8b34893a7166508dfd205fdceb (diff)
Added CVE-2019-19118 to the security archive.
Diffstat (limited to 'docs/releases')
-rw-r--r--docs/releases/security.txt13
1 files changed, 13 insertions, 0 deletions
diff --git a/docs/releases/security.txt b/docs/releases/security.txt
index ef70cac0d9..e925b8304d 100644
--- a/docs/releases/security.txt
+++ b/docs/releases/security.txt
@@ -1029,3 +1029,16 @@ Versions affected
* Django 2.2 :commit:`(patch) <cf694e6852b0da7799f8b53f1fb2f7d20cf17534>`
* Django 2.1 :commit:`(patch) <5d50a2e5fa36ad23ab532fc54cf4073de84b3306>`
* Django 1.11 :commit:`(patch) <869b34e9b3be3a4cfcb3a145f218ffd3f5e3fd79>`
+
+December 2, 2019 - :cve:`2019-19118`
+------------------------------------
+
+Privilege escalation in the Django admin. `Full description
+<https://www.djangoproject.com/weblog/2019/dec/02/security-releases/>`__
+
+Versions affected
+~~~~~~~~~~~~~~~~~
+
+* Django 3.0 :commit:`(patch) <092cd66cf3c3e175acce698d6ca2012068d878fa>`
+* Django 2.2 :commit:`(patch) <36f580a17f0b3cb087deadf3b65eea024f479c21>`
+* Django 2.1 :commit:`(patch) <103ebe2b5ff1b2614b85a52c239f471904d26244>`