123456789101112131415161718192021 |
- ==========================
- Django 3.1.6 release notes
- ==========================
- *February 1, 2021*
- Django 3.1.6 fixes a security issue with severity "low" and a bug in 3.1.5.
- CVE-2021-3281: Potential directory-traversal via ``archive.extract()``
- ======================================================================
- The ``django.utils.archive.extract()`` function, used by
- :option:`startapp --template` and :option:`startproject --template`, allowed
- directory-traversal via an archive with absolute paths or relative paths with
- dot segments.
- Bugfixes
- ========
- * Fixed an admin layout issue in Django 3.1 where changelist filter controls
- would become squashed (:ticket:`32391`).
|