diff options
| author | Florian Apolloner <florian@apolloner.eu> | 2021-12-27 14:48:03 +0100 |
|---|---|---|
| committer | Carlton Gibson <carlton.gibson@noumenal.es> | 2022-01-04 10:02:05 +0100 |
| commit | 968a3d01fa79f055f93a1c3ed1535ecbcbdbb842 (patch) | |
| tree | ac977466ff6d3ae6daf70389f7895aad4c4e5981 /docs/releases | |
| parent | ccafad2e429468c518c80fb178f9e7a3f06e78e1 (diff) | |
Fixed CVE-2021-45115 -- Prevented DoS vector in UserAttributeSimilarityValidator.
Thanks Chris Bailey for the report.
Co-authored-by: Adam Johnson <me@adamj.eu>
Diffstat (limited to 'docs/releases')
| -rw-r--r-- | docs/releases/2.2.26.txt | 14 | ||||
| -rw-r--r-- | docs/releases/3.2.11.txt | 14 | ||||
| -rw-r--r-- | docs/releases/4.0.1.txt | 14 |
3 files changed, 40 insertions, 2 deletions
diff --git a/docs/releases/2.2.26.txt b/docs/releases/2.2.26.txt index 12e9923a19..3444c491db 100644 --- a/docs/releases/2.2.26.txt +++ b/docs/releases/2.2.26.txt @@ -7,4 +7,16 @@ Django 2.2.26 release notes Django 2.2.26 fixes one security issue with severity "medium" and two security issues with severity "low" in 2.2.25. -... +CVE-2021-45115: Denial-of-service possibility in ``UserAttributeSimilarityValidator`` +===================================================================================== + +:class:`.UserAttributeSimilarityValidator` incurred significant overhead +evaluating submitted password that were artificially large in relative to the +comparison values. On the assumption that access to user registration was +unrestricted this provided a potential vector for a denial-of-service attack. + +In order to mitigate this issue, relatively long values are now ignored by +``UserAttributeSimilarityValidator``. + +This issue has severity "medium" according to the :ref:`Django security policy +<security-disclosure>`. diff --git a/docs/releases/3.2.11.txt b/docs/releases/3.2.11.txt index b88f0f79ff..621139033c 100644 --- a/docs/releases/3.2.11.txt +++ b/docs/releases/3.2.11.txt @@ -7,4 +7,16 @@ Django 3.2.11 release notes Django 3.2.11 fixes one security issue with severity "medium" and two security issues with severity "low" in 3.2.10. -... +CVE-2021-45115: Denial-of-service possibility in ``UserAttributeSimilarityValidator`` +===================================================================================== + +:class:`.UserAttributeSimilarityValidator` incurred significant overhead +evaluating submitted password that were artificially large in relative to the +comparison values. On the assumption that access to user registration was +unrestricted this provided a potential vector for a denial-of-service attack. + +In order to mitigate this issue, relatively long values are now ignored by +``UserAttributeSimilarityValidator``. + +This issue has severity "medium" according to the :ref:`Django security policy +<security-disclosure>`. diff --git a/docs/releases/4.0.1.txt b/docs/releases/4.0.1.txt index 8d3c0ae6f2..9429a8afff 100644 --- a/docs/releases/4.0.1.txt +++ b/docs/releases/4.0.1.txt @@ -7,6 +7,20 @@ Django 4.0.1 release notes Django 4.0.1 fixes one security issue with severity "medium", two security issues with severity "low", and several bugs in 4.0. +CVE-2021-45115: Denial-of-service possibility in ``UserAttributeSimilarityValidator`` +===================================================================================== + +:class:`.UserAttributeSimilarityValidator` incurred significant overhead +evaluating submitted password that were artificially large in relative to the +comparison values. On the assumption that access to user registration was +unrestricted this provided a potential vector for a denial-of-service attack. + +In order to mitigate this issue, relatively long values are now ignored by +``UserAttributeSimilarityValidator``. + +This issue has severity "medium" according to the :ref:`Django security policy +<security-disclosure>`. + Bugfixes ======== |
