4.2.16.txt 1.1 KB

1234567891011121314151617181920212223242526
  1. ===========================
  2. Django 4.2.16 release notes
  3. ===========================
  4. *September 3, 2024*
  5. Django 4.2.16 fixes one security issue with severity "moderate" and one
  6. security issue with severity "low" in 4.2.15.
  7. CVE-2024-45230: Potential denial-of-service vulnerability in ``django.utils.html.urlize()``
  8. ===========================================================================================
  9. :tfilter:`urlize` and :tfilter:`urlizetrunc` were subject to a potential
  10. denial-of-service attack via very large inputs with a specific sequence of
  11. characters.
  12. CVE-2024-45231: Potential user email enumeration via response status on password reset
  13. ======================================================================================
  14. Due to unhandled email sending failures, the
  15. :class:`~django.contrib.auth.forms.PasswordResetForm` class allowed remote
  16. attackers to enumerate user emails by issuing password reset requests and
  17. observing the outcomes.
  18. To mitigate this risk, exceptions occurring during password reset email sending
  19. are now handled and logged using the :ref:`django-contrib-auth-logger` logger.