diff --git a/docs/releases/security.txt b/docs/releases/security.txt index 8c8082c9ef..a59c6a145d 100644 --- a/docs/releases/security.txt +++ b/docs/releases/security.txt @@ -36,6 +36,19 @@ Issues under Django's security process All security issues have been handled under versions of Django's security process. These are listed below. +July 1, 2021 - :cve:`2021-35042` +-------------------------------- + +Potential SQL injection via unsanitized ``QuerySet.order_by()`` input. `Full +description +`__ + +Versions affected +~~~~~~~~~~~~~~~~~ + +* Django 3.2 :commit:`(patch) ` +* Django 3.1 :commit:`(patch) <0bd57a879a0d54920bb9038a732645fb917040e9>` + June 2, 2021 - :cve:`2021-33203` --------------------------------