From ecd502cfdb57706dd0e84d9928934bcae6b1ef25 Mon Sep 17 00:00:00 2001 From: Tim Graham Date: Mon, 1 Feb 2016 12:42:37 -0500 Subject: [PATCH] Added CVE-2016-2048 to the security archive. --- docs/releases/security.txt | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/docs/releases/security.txt b/docs/releases/security.txt index cbd5585244c..ddb4871a7b7 100644 --- a/docs/releases/security.txt +++ b/docs/releases/security.txt @@ -690,3 +690,15 @@ Versions affected * Django 1.8 `(patch) `__ * Django 1.7 `(patch) `__ + +February 1, 2016 -- CVE-2016-2048 +--------------------------------- + +`CVE-2016-2048 `_: +User with "change" but not "add" permission can create objects for ``ModelAdmin``’s with ``save_as=True``. +`Full description `__ + +Versions affected +~~~~~~~~~~~~~~~~~ + +* Django 1.9 `(patch) `__