diff --git a/docs/releases/1.7.1.txt b/docs/releases/1.7.1.txt index f743447d56..0a5a0163b8 100644 --- a/docs/releases/1.7.1.txt +++ b/docs/releases/1.7.1.txt @@ -91,3 +91,9 @@ Bugfixes (:ticket:`23560`). * Fixed ``deepcopy`` on ``ErrorList`` (:ticket:`23594`). + +* Made the :mod:`~django.contrib.admindocs` view to browse view details check + if the view specified in the URL exists in the URLconf. Previously it was + possible to import arbitrary packages from the Python path. This was not + considered a security issue because ``admindocs`` is only accessible to staff + users (:ticket:`23601`). diff --git a/docs/releases/1.8.txt b/docs/releases/1.8.txt index 434e91e9a5..01e48b75e4 100644 --- a/docs/releases/1.8.txt +++ b/docs/releases/1.8.txt @@ -76,14 +76,6 @@ Minor features ` to control whether or not the full count of objects should be displayed on a filtered admin page. -:mod:`django.contrib.admindocs` -^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ - -* The view to browse view details now checks if the view specified in the URL - exists in the URLconf. Previously it was possible to import arbitrary - packages from the Python path. This was not considered a security issue - because ``admindocs`` is only accessible to staff users. - :mod:`django.contrib.auth` ^^^^^^^^^^^^^^^^^^^^^^^^^^