From a76c52b19a221147f3a903848f711daa367e2e20 Mon Sep 17 00:00:00 2001 From: Mariusz Felisiak Date: Mon, 4 Mar 2024 10:10:35 +0100 Subject: [PATCH] [4.2.x] Added CVE-2024-27351 to security archive. Backport of da39ae4b5f056a332b5c48402a2ae11767e7d577 from main --- docs/releases/security.txt | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/docs/releases/security.txt b/docs/releases/security.txt index 7df74adb82d..404af4d00fc 100644 --- a/docs/releases/security.txt +++ b/docs/releases/security.txt @@ -36,6 +36,17 @@ Issues under Django's security process All security issues have been handled under versions of Django's security process. These are listed below. +March 4, 2024 - :cve:`2024-27351` +--------------------------------- + +Potential regular expression denial-of-service in +``django.utils.text.Truncator.words()``. `Full description +`__ + +* Django 5.0 :commit:`(patch) <3394fc6132436eca89e997083bae9985fb7e761e>` +* Django 4.2 :commit:`(patch) <3c9a2771cc80821e041b16eb36c1c37af5349d4a>` +* Django 3.2 :commit:`(patch) <072963e4c4d0b3a7a8c5412bc0c7d27d1a9c3521>` + February 6, 2024 - :cve:`2024-24680` ------------------------------------