diff --git a/docs/releases/security.txt b/docs/releases/security.txt index 2d60fe1caed..c963814c4d5 100644 --- a/docs/releases/security.txt +++ b/docs/releases/security.txt @@ -582,3 +582,32 @@ Versions affected * Django 1.7 `(patch) `__ * Django 1.8 `(patch) `_ + +March 18, 2015 - CVE-2015-2316 +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +`CVE-2015-2316 `_: +Denial-of-service possibility with ``strip_tags()``. +`Full description `__ + +Versions affected +----------------- + +* Django 1.6 `(patch) `__ +* Django 1.7 `(patch) `__ +* Django 1.8 `(patch) `__ + +March 18, 2015 - CVE-2015-2317 +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +`CVE-2015-2317 `_: +Mitigated possible XSS attack via user-supplied redirect URLs. +`Full description `__ + +Versions affected +----------------- + +* Django 1.4 `(patch) `__ +* Django 1.6 `(patch) `__ +* Django 1.7 `(patch) `__ +* Django 1.8 `(patch) `__