Django 4.2.11 release notesLien vers cette rubrique
March 4, 2024
Django 4.2.11 fixes a security issue with severity « moderate » and a regression in 4.2.10.
CVE-2024-27351: Potential regular expression denial-of-service in django.utils.text.Truncator.words()Lien vers cette rubrique
django.utils.text.Truncator.words() method (with html=True) and
truncatewords_html template filter were subject to a potential
regular expression denial-of-service attack using a suitably crafted string
(follow up to CVE 2019-14232 and CVE 2023-43665).
Correction de boguesLien vers cette rubrique
Fixed a regression in Django 4.2.10 where
intcommatemplate filter could return a leading comma for string representation of floats (#35172).