---
title: "Notes de publication de Django 2.2.4"
version: 5.1
locale: fr
source: https://docs.djangoproject.com/fr/5.1/releases/2.2.4/
canonical: https://djangodocs.dev/fr/5.1/releases/2.2.4/
---
# Notes de publication de Django 2.2.4

*August 1, 2019*

Django 2.2.4 fixes security issues and several bugs in 2.2.3.

## CVE-2019-14232: Denial-of-service possibility in `django.utils.text.Truncator`

If `django.utils.text.Truncator`’s `chars()` and `words()` methods
were passed the `html=True` argument, they were extremely slow to evaluate
certain inputs due to a catastrophic backtracking vulnerability in a regular
expression. The `chars()` and `words()` methods are used to implement the
[`truncatechars_html`](/fr/5.1/ref/templates/builtins/#std-templatefilter-truncatechars_html) and [`truncatewords_html`](/fr/5.1/ref/templates/builtins/#std-templatefilter-truncatewords_html) template
filters, which were thus vulnerable.

The regular expressions used by `Truncator` have been simplified in order to
avoid potential backtracking issues. As a consequence, trailing punctuation may
now at times be included in the truncated output.

## CVE-2019-14233: Denial-of-service possibility in `strip_tags()`

Due to the behavior of the underlying `HTMLParser`,
[`django.utils.html.strip_tags()`](/fr/5.1/ref/utils/#django.utils.html.strip_tags) would be extremely slow to evaluate
certain inputs containing large sequences of nested incomplete HTML entities.
The `strip_tags()` method is used to implement the corresponding
[`striptags`](/fr/5.1/ref/templates/builtins/#std-templatefilter-striptags) template filter, which was thus also vulnerable.

`strip_tags()` now avoids recursive calls to `HTMLParser` when progress
removing tags, but necessarily incomplete HTML entities, stops being made.

Remember that absolutely NO guarantee is provided about the results of
`strip_tags()` being HTML safe. So NEVER mark safe the result of a
`strip_tags()` call without escaping it first, for example with
[`django.utils.html.escape()`](/fr/5.1/ref/utils/#django.utils.html.escape).

## CVE-2019-14234: SQL injection possibility in key and index lookups for `JSONField`/`HStoreField`

[`Key and index lookups`](/fr/5.1/topics/db/queries/#std-fieldlookup-jsonfield.key) for
`django.contrib.postgres.fields.JSONField` and [`key lookups`](/fr/5.1/ref/contrib/postgres/fields/#std-fieldlookup-hstorefield.key) for [`HStoreField`](/fr/5.1/ref/contrib/postgres/fields/#django.contrib.postgres.fields.HStoreField)
were subject to SQL injection, using a suitably crafted dictionary, with
dictionary expansion, as the `**kwargs` passed to `QuerySet.filter()`.

## CVE-2019-14235: Potential memory exhaustion in `django.utils.encoding.uri_to_iri()`

If passed certain inputs, [`django.utils.encoding.uri_to_iri()`](/fr/5.1/ref/utils/#django.utils.encoding.uri_to_iri) could lead
to significant memory usage due to excessive recursion when re-percent-encoding
invalid UTF-8 octet sequences.

`uri_to_iri()` now avoids recursion when re-percent-encoding invalid UTF-8
octet sequences.

## Correction de bogues

- Fixed a regression in Django 2.2 when ordering a `QuerySet.union()`,
  `intersection()`, or `difference()` by a field type present more than
  once results in the wrong ordering being used ([#30628](https://code.djangoproject.com/ticket/30628)).
- Fixed a migration crash on PostgreSQL when adding a check constraint
  with a `contains` lookup on
  [`DateRangeField`](/fr/5.1/ref/contrib/postgres/fields/#django.contrib.postgres.fields.DateRangeField) or
  [`DateTimeRangeField`](/fr/5.1/ref/contrib/postgres/fields/#django.contrib.postgres.fields.DateTimeRangeField), if the right
  hand side of an expression is the same type ([#30621](https://code.djangoproject.com/ticket/30621)).
- Fixed a regression in Django 2.2 where auto-reloader crashes if a file path
  contains null characters (`'\x00'`) ([#30506](https://code.djangoproject.com/ticket/30506)).
- Fixed a regression in Django 2.2 where auto-reloader crashes if a translation
  directory cannot be resolved ([#30647](https://code.djangoproject.com/ticket/30647)).
