From 8feb2a49fa37528823cc900bbd9609319738193e Mon Sep 17 00:00:00 2001 From: Mariusz Felisiak Date: Thu, 1 Jul 2021 09:57:08 +0200 Subject: [PATCH] Added CVE-2021-35042 to security archive. --- docs/releases/security.txt | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/docs/releases/security.txt b/docs/releases/security.txt index 8c8082c9ef..a59c6a145d 100644 --- a/docs/releases/security.txt +++ b/docs/releases/security.txt @@ -36,6 +36,19 @@ Issues under Django's security process All security issues have been handled under versions of Django's security process. These are listed below. +July 1, 2021 - :cve:`2021-35042` +-------------------------------- + +Potential SQL injection via unsanitized ``QuerySet.order_by()`` input. `Full +description +`__ + +Versions affected +~~~~~~~~~~~~~~~~~ + +* Django 3.2 :commit:`(patch) ` +* Django 3.1 :commit:`(patch) <0bd57a879a0d54920bb9038a732645fb917040e9>` + June 2, 2021 - :cve:`2021-33203` --------------------------------