2020-05-14 06:22:54 +02:00
|
|
|
===========================
|
|
|
|
Django 2.2.13 release notes
|
|
|
|
===========================
|
|
|
|
|
2020-06-03 09:13:16 +02:00
|
|
|
*June 3, 2020*
|
2020-05-14 06:22:54 +02:00
|
|
|
|
2020-05-28 10:26:41 +02:00
|
|
|
Django 2.2.13 fixes two security issues and a regression in 2.2.12.
|
2020-05-14 06:22:54 +02:00
|
|
|
|
2020-05-20 11:45:31 +02:00
|
|
|
CVE-2020-13254: Potential data leakage via malformed memcached keys
|
|
|
|
===================================================================
|
|
|
|
|
|
|
|
In cases where a memcached backend does not perform key validation, passing
|
|
|
|
malformed cache keys could result in a key collision, and potential data
|
|
|
|
leakage. In order to avoid this vulnerability, key validation is added to the
|
|
|
|
memcached cache backends.
|
|
|
|
|
2020-05-26 09:51:02 +02:00
|
|
|
CVE-2020-13596: Possible XSS via admin ``ForeignKeyRawIdWidget``
|
|
|
|
================================================================
|
|
|
|
|
|
|
|
Query parameters for the admin ``ForeignKeyRawIdWidget`` were not properly URL
|
|
|
|
encoded, posing an XSS attack vector. ``ForeignKeyRawIdWidget`` now
|
|
|
|
ensures query parameters are correctly URL encoded.
|
|
|
|
|
2020-05-14 06:22:54 +02:00
|
|
|
Bugfixes
|
|
|
|
========
|
|
|
|
|
2020-05-28 10:26:41 +02:00
|
|
|
* Fixed a regression in Django 2.2.12 that affected translation loading for
|
|
|
|
apps providing translations for territorial language variants as well as a
|
|
|
|
generic language, where the project has different plural equations for the
|
|
|
|
language (:ticket:`31570`).
|
2020-06-02 14:32:43 +02:00
|
|
|
|
|
|
|
* Tracking a jQuery security release, upgraded the version of jQuery used by
|
|
|
|
the admin from 3.3.1 to 3.5.1.
|