Skip to content

Commit d0e3eb8

Browse files
committed
[1.11.x] Added CVE-2020-7471 to security archive.
Backport of d8b2ccb from master
1 parent 9a62ed5 commit d0e3eb8

1 file changed

Lines changed: 13 additions & 0 deletions

File tree

docs/releases/security.txt

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1042,3 +1042,16 @@ Versions affected
10421042
* Django 3.0 :commit:`(patch) <302a4ff1e8b1c798aab97673909c7a3dfda42c26>`
10431043
* Django 2.2 :commit:`(patch) <4d334bea06cac63dc1272abcec545b85136cca0e>`
10441044
* Django 1.11 :commit:`(patch) <f4cff43bf921fcea6a29b726eb66767f67753fa2>`
1045+
1046+
February 3, 2020 - :cve:`2020-7471`
1047+
-----------------------------------
1048+
1049+
Potential SQL injection via ``StringAgg(delimiter)``. `Full description
1050+
<https://www.djangoproject.com/weblog/2020/feb/03/security-releases/>`__
1051+
1052+
Versions affected
1053+
~~~~~~~~~~~~~~~~~
1054+
1055+
* Django 3.0 :commit:`(patch) <505826b469b16ab36693360da9e11fd13213421b>`
1056+
* Django 2.2 :commit:`(patch) <c67a368c16e4680b324b4f385398d638db4d8147>`
1057+
* Django 1.11 :commit:`(patch) <001b0634cd309e372edb6d7d95d083d02b8e37bd>`

0 commit comments

Comments
 (0)