---
title: "Catatan terbitan Django 1.11.11"
version: 4.2
locale: id
source: https://docs.djangoproject.com/id/4.2/releases/1.11.11/
canonical: https://djangodocs.dev/id/4.2/releases/1.11.11/
---
# Catatan terbitan Django 1.11.11

*6 Maret 2018*

Django 1.11.11 memperbaiki dua masalah keamanan di 1.11.10.

## CVE-2018-7536: Denial-of-service possibility in `urlize` and `urlizetrunc` template filters

The `django.utils.html.urlize()` function was extremely slow to evaluate
certain inputs due to catastrophic backtracking vulnerabilities in two regular
expressions. The `urlize()` function is used to implement the `urlize` and
`urlizetrunc` template filters, which were thus vulnerable.

The problematic regular expressions are replaced with parsing logic that
behaves similarly.

## CVE-2018-7537: Denial-of-service possibility in `truncatechars_html` and `truncatewords_html` template filters

If `django.utils.text.Truncator`'s `chars()` and `words()` methods were
passed the `html=True` argument, they were extremely slow to evaluate certain
inputs due to a catastrophic backtracking vulnerability in a regular
expression. The `chars()` and `words()` methods are used to implement the
`truncatechars_html` and `truncatewords_html` template filters, which were
thus vulnerable.

The backtracking problem in the regular expression is fixed.
