Fixed typo in release notes.

This commit is contained in:
David Smith 2022-02-02 06:17:57 +00:00 committed by GitHub
parent ca88caa103
commit 770d3e6a4c
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
3 changed files with 3 additions and 3 deletions

View File

@ -12,7 +12,7 @@ CVE-2022-22818: Possible XSS via ``{% debug %}`` template tag
The ``{% debug %}`` template tag didn't properly encode the current context, The ``{% debug %}`` template tag didn't properly encode the current context,
posing an XSS attack vector. posing an XSS attack vector.
In order to avoid this vulnerability, ``{% debug %}`` no longer outputs an In order to avoid this vulnerability, ``{% debug %}`` no longer outputs
information when the ``DEBUG`` setting is ``False``, and it ensures all context information when the ``DEBUG`` setting is ``False``, and it ensures all context
variables are correctly escaped when the ``DEBUG`` setting is ``True``. variables are correctly escaped when the ``DEBUG`` setting is ``True``.

View File

@ -12,7 +12,7 @@ CVE-2022-22818: Possible XSS via ``{% debug %}`` template tag
The ``{% debug %}`` template tag didn't properly encode the current context, The ``{% debug %}`` template tag didn't properly encode the current context,
posing an XSS attack vector. posing an XSS attack vector.
In order to avoid this vulnerability, ``{% debug %}`` no longer outputs an In order to avoid this vulnerability, ``{% debug %}`` no longer outputs
information when the ``DEBUG`` setting is ``False``, and it ensures all context information when the ``DEBUG`` setting is ``False``, and it ensures all context
variables are correctly escaped when the ``DEBUG`` setting is ``True``. variables are correctly escaped when the ``DEBUG`` setting is ``True``.

View File

@ -14,7 +14,7 @@ CVE-2022-22818: Possible XSS via ``{% debug %}`` template tag
The ``{% debug %}`` template tag didn't properly encode the current context, The ``{% debug %}`` template tag didn't properly encode the current context,
posing an XSS attack vector. posing an XSS attack vector.
In order to avoid this vulnerability, ``{% debug %}`` no longer outputs an In order to avoid this vulnerability, ``{% debug %}`` no longer outputs
information when the ``DEBUG`` setting is ``False``, and it ensures all context information when the ``DEBUG`` setting is ``False``, and it ensures all context
variables are correctly escaped when the ``DEBUG`` setting is ``True``. variables are correctly escaped when the ``DEBUG`` setting is ``True``.