2024-08-27 14:20:59 +02:00
|
|
|
===========================
|
|
|
|
Django 4.2.16 release notes
|
|
|
|
===========================
|
|
|
|
|
|
|
|
*September 3, 2024*
|
|
|
|
|
|
|
|
Django 4.2.16 fixes one security issue with severity "moderate" and one
|
2024-08-27 14:46:12 +02:00
|
|
|
security issue with severity "low" in 4.2.15.
|
2024-08-27 14:20:59 +02:00
|
|
|
|
2024-08-12 15:17:57 +02:00
|
|
|
CVE-2024-45230: Potential denial-of-service vulnerability in ``django.utils.html.urlize()``
|
|
|
|
===========================================================================================
|
|
|
|
|
|
|
|
:tfilter:`urlize` and :tfilter:`urlizetrunc` were subject to a potential
|
|
|
|
denial-of-service attack via very large inputs with a specific sequence of
|
|
|
|
characters.
|