2021-12-27 21:42:14 +08:00
|
|
|
===========================
|
|
|
|
Django 2.2.26 release notes
|
|
|
|
===========================
|
|
|
|
|
|
|
|
*January 4, 2022*
|
|
|
|
|
|
|
|
Django 2.2.26 fixes one security issue with severity "medium" and two security
|
|
|
|
issues with severity "low" in 2.2.25.
|
|
|
|
|
2021-12-27 21:48:03 +08:00
|
|
|
CVE-2021-45115: Denial-of-service possibility in ``UserAttributeSimilarityValidator``
|
|
|
|
=====================================================================================
|
|
|
|
|
|
|
|
:class:`.UserAttributeSimilarityValidator` incurred significant overhead
|
|
|
|
evaluating submitted password that were artificially large in relative to the
|
|
|
|
comparison values. On the assumption that access to user registration was
|
|
|
|
unrestricted this provided a potential vector for a denial-of-service attack.
|
|
|
|
|
|
|
|
In order to mitigate this issue, relatively long values are now ignored by
|
|
|
|
``UserAttributeSimilarityValidator``.
|
|
|
|
|
|
|
|
This issue has severity "medium" according to the :ref:`Django security policy
|
|
|
|
<security-disclosure>`.
|