summaryrefslogtreecommitdiff
path: root/docs/releases/3.2.11.txt
diff options
context:
space:
mode:
Diffstat (limited to 'docs/releases/3.2.11.txt')
-rw-r--r--docs/releases/3.2.11.txt14
1 files changed, 13 insertions, 1 deletions
diff --git a/docs/releases/3.2.11.txt b/docs/releases/3.2.11.txt
index b88f0f79ff..621139033c 100644
--- a/docs/releases/3.2.11.txt
+++ b/docs/releases/3.2.11.txt
@@ -7,4 +7,16 @@ Django 3.2.11 release notes
Django 3.2.11 fixes one security issue with severity "medium" and two security
issues with severity "low" in 3.2.10.
-...
+CVE-2021-45115: Denial-of-service possibility in ``UserAttributeSimilarityValidator``
+=====================================================================================
+
+:class:`.UserAttributeSimilarityValidator` incurred significant overhead
+evaluating submitted password that were artificially large in relative to the
+comparison values. On the assumption that access to user registration was
+unrestricted this provided a potential vector for a denial-of-service attack.
+
+In order to mitigate this issue, relatively long values are now ignored by
+``UserAttributeSimilarityValidator``.
+
+This issue has severity "medium" according to the :ref:`Django security policy
+<security-disclosure>`.