-
-
Notifications
You must be signed in to change notification settings - Fork 32.6k
Comparing changes
Open a pull request
base repository: django/django
base: 4.2.13
head repository: django/django
compare: 4.2.15
- 17 commits
- 24 files changed
- 8 contributors
Commits on May 7, 2024
-
Configuration menu - View commit details
-
Copy full SHA for d26c883 - Browse repository at this point
Copy the full SHA d26c883View commit details
Commits on Jul 3, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 446cdab - Browse repository at this point
Copy the full SHA 446cdabView commit details
Commits on Jul 9, 2024
-
[4.2.x] Fixed CVE-2024-38875 -- Mitigated potential DoS in urlize and…
… urlizetrunc template filters. Thank you to Elias Myllymäki for the report. Co-authored-by: Sarah Boyce <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 79f3687 - Browse repository at this point
Copy the full SHA 79f3687View commit details -
[4.2.x] Fixed CVE-2024-39329 -- Standarized timing of verify_password…
…() when checking unusuable passwords. Refs #20760. Thanks Michael Manfre for the fix and to Adam Johnson for the review.
Configuration menu - View commit details
-
Copy full SHA for 156d318 - Browse repository at this point
Copy the full SHA 156d318View commit details -
[4.2.x] Fixed CVE-2024-39330 -- Added extra file name validation in S…
…torage's save method. Thanks to Josh Schneier for the report, and to Carlton Gibson and Sarah Boyce for the reviews.
Configuration menu - View commit details
-
Copy full SHA for 2b00edc - Browse repository at this point
Copy the full SHA 2b00edcView commit details -
[4.2.x] Fixed CVE-2024-39614 -- Mitigated potential DoS in get_suppor…
…ted_language_variant(). Language codes are now parsed with a maximum length limit of 500 chars. Thanks to MProgrammer for the report.
Configuration menu - View commit details
-
Copy full SHA for 17358fb - Browse repository at this point
Copy the full SHA 17358fbView commit details -
Configuration menu - View commit details
-
Copy full SHA for 98cf264 - Browse repository at this point
Copy the full SHA 98cf264View commit details -
Configuration menu - View commit details
-
Copy full SHA for 72f6c7d - Browse repository at this point
Copy the full SHA 72f6c7dView commit details -
[4.2.x] Added CVE-2024-38875, CVE-2024-39329, CVE-2024-39330, and CVE…
…-2024-39614 to security archive. Backport of e095c76 from main.
Configuration menu - View commit details
-
Copy full SHA for 8e59e33 - Browse repository at this point
Copy the full SHA 8e59e33View commit details
Commits on Jul 11, 2024
-
Configuration menu - View commit details
-
Copy full SHA for c5d196a - Browse repository at this point
Copy the full SHA c5d196aView commit details
Commits on Jul 25, 2024
-
[4.2.x] Fixed #35627 -- Raised a LookupError rather than an unhandled…
Configuration menu - View commit details
-
Copy full SHA for 96a3497 - Browse repository at this point
Copy the full SHA 96a3497View commit details
Commits on Jul 31, 2024
-
[4.2.x] Added stub release notes and release date for 4.2.15.
Backport of 3f88089 from main.
Configuration menu - View commit details
-
Copy full SHA for 7b1a76f - Browse repository at this point
Copy the full SHA 7b1a76fView commit details -
[4.2.x] Fixed CVE-2024-41989 -- Prevented excessive memory consumptio…
…n in floatformat. Thanks Elias Myllymäki for the report. Co-authored-by: Shai Berger <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for fc76660 - Browse repository at this point
Copy the full SHA fc76660View commit details -
[4.2.x] Fixed CVE-2024-41990 -- Mitigated potential DoS in urlize and…
… urlizetrunc template filters. Thanks to MProgrammer for the report.
Configuration menu - View commit details
-
Copy full SHA for d0a82e2 - Browse repository at this point
Copy the full SHA d0a82e2View commit details -
[4.2.x] Fixed CVE-2024-41991 -- Prevented potential ReDoS in django.u…
…tils.html.urlize() and AdminURLFieldWidget. Thanks Seokchan Yoon for the report. Co-authored-by: Sarah Boyce <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for efea1ef - Browse repository at this point
Copy the full SHA efea1efView commit details -
[4.2.x] Fixed CVE-2024-42005 -- Mitigated QuerySet.values() SQL injec…
…tion attacks against JSON fields. Thanks Eyal (eyalgabay) for the report.
Configuration menu - View commit details
-
Copy full SHA for f4af67b - Browse repository at this point
Copy the full SHA f4af67bView commit details
Commits on Aug 6, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 4d32ebc - Browse repository at this point
Copy the full SHA 4d32ebcView commit details
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff 4.2.13...4.2.15