From 996ac768e3e5df837b19881ddd9e6e1a91709e22 Mon Sep 17 00:00:00 2001 From: Simon Charette Date: Wed, 27 Aug 2014 23:04:23 -0400 Subject: [PATCH] [1.6.x] Fixed #23375 -- Added missing security issues to the archive. Backport of c9c0be3 from master --- docs/releases/security.txt | 144 +++++++++++++++++++++++++++++++------ 1 file changed, 123 insertions(+), 21 deletions(-) diff --git a/docs/releases/security.txt b/docs/releases/security.txt index d9c511efb8f..d48d0b4dc32 100644 --- a/docs/releases/security.txt +++ b/docs/releases/security.txt @@ -450,52 +450,154 @@ Versions affected * Django 1.5 `(patch) `__ -April 21, 2014 - CVE-2014-2014-0472 -~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +April 21, 2014 - CVE-2014-0472 +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -`CVE-2014-0472 `_: Unexpected code execution using ``reverse()``. `Full description `_ +`CVE-2014-0472 `_: Unexpected code execution using ``reverse()``. `Full description `__ Versions affected ----------------- -* Django 1.4 `(patch `_) +* Django 1.4 `(patch) `__ -* Django 1.5 `(patch `_) +* Django 1.5 `(patch) `__ -* Django 1.6 `(patch `_) +* Django 1.6 `(patch) `__ -* Django 1.7 `(patch `_) +* Django 1.7 `(patch) `__ -April 21, 2014 - CVE-2014-2014-0473 -~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +April 21, 2014 - CVE-2014-0473 +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -`CVE-2014-0473 `_: Caching of anonymous pages could reveal CSRF token. `Full description `_ +`CVE-2014-0473 `_: Caching of anonymous pages could reveal CSRF token. `Full description `__ Versions affected ----------------- -* Django 1.4 `(patch `_) +* Django 1.4 `(patch) `__ -* Django 1.5 `(patch `_) +* Django 1.5 `(patch) `__ -* Django 1.6 `(patch `_) +* Django 1.6 `(patch) `__ -* Django 1.7 `(patch `_) +* Django 1.7 `(patch) `__ -April 21, 2014 - CVE-2014-2014-0472 -~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +April 21, 2014 - CVE-2014-0474 +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -`CVE-2014-0474 `_: MySQL typecasting causes unexpected query results. `Full description `_ +`CVE-2014-0474 `_: MySQL typecasting causes unexpected query results. `Full description `__ Versions affected ----------------- -* Django 1.4 `(patch `_) +* Django 1.4 `(patch) `__ -* Django 1.5 `(patch `_) +* Django 1.5 `(patch) `__ -* Django 1.6 `(patch `_) +* Django 1.6 `(patch) `__ -* Django 1.7 `(patch `_) +* Django 1.7 `(patch) `__ + + +May 18, 2014 - CVE-2014-1418 +~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +`CVE-2014-1418 `_: Caches may be allowed to store and serve private data. `Full description `__ + +Versions affected +----------------- + +* Django 1.4 `(patch) `__ + +* Django 1.5 `(patch) `__ + +* Django 1.6 `(patch) `__ + +* Django 1.7 `(patch) `__ + + +May 18, 2014 - CVE-2014-3730 +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +`CVE-2014-3730 `_: Malformed URLs from user input incorrectly validated. `Full description `__ + +Versions affected +----------------- + +* Django 1.4 `(patch) `__ + +* Django 1.5 `(patch) `__ + +* Django 1.6 `(patch) `__ + +* Django 1.7 `(patch) `__ + + +August 20, 2014 - CVE-2014-0480 +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +`CVE-2014-0480 `_: reverse() can generate URLs pointing to other hosts. `Full description `__ + +Versions affected +----------------- + +* Django 1.4 `(patch) `__ + +* Django 1.5 `(patch) `__ + +* Django 1.6 `(patch) `__ + +* Django 1.7 `(patch) `__ + + +August 20, 2014 - CVE-2014-0481 +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +`CVE-2014-0481 `_: File upload denial of service. `Full description `__ + +Versions affected +----------------- + +* Django 1.4 `(patch) `__ + +* Django 1.5 `(patch) `__ + +* Django 1.6 `(patch) `__ + +* Django 1.7 `(patch) `__ + + +August 20, 2014 - CVE-2014-0482 +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +`CVE-2014-0482 `_: RemoteUserMiddleware session hijacking. `Full description `__ + +Versions affected +----------------- + +* Django 1.4 `(patch) `__ + +* Django 1.5 `(patch) `__ + +* Django 1.6 `(patch) `__ + +* Django 1.7 `(patch) `__ + + +August 20, 2014 - CVE-2014-0483 +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +`CVE-2014-0483 `_: Data leakage via querystring manipulation in admin. `Full description `__ + +Versions affected +----------------- + +* Django 1.4 `(patch) `__ + +* Django 1.5 `(patch) `__ + +* Django 1.6 `(patch) `__ + +* Django 1.7 `(patch) `__