26100 Commits

Author SHA1 Message Date
Carlton Gibson
df59146825 [2.1.x] Removed issue reporter name from 2.1.15 release notes.
Backport of 368b8d20aaa16f0ef763759a0a87d986ef460584 from master
2019-12-02 10:04:16 +01:00
Carlton Gibson
98c7dacecf [2.1.x] Post-release version bump. 2019-12-02 09:29:11 +01:00
Carlton Gibson
3baf68b4ef [2.1.x] Bumped version for 2.1.5 release. 2.1.15 2019-12-02 09:20:52 +01:00
Carlton Gibson
2fc998e3ba [2.1.x] Added release date for 2.1.15.
Backport of e31d1852671866f6e52d55f9b7925ecad711fcf5 from master
2019-12-02 09:14:54 +01:00
Carlton Gibson
103ebe2b5f Fixed CVE-2019-19118 -- Required edit permissions on parent model for editable inlines in admin.
Thank you to Shen Ying for reporting this issue.
2019-12-02 08:58:35 +01:00
Mariusz Felisiak
f57f81a7fe [2.1.x] Refs #30953 -- Added 2.1.15 release note for 0107e3d1058f653f66032f7fd3a0bd61e96bf782.
Backport of 39e39d0ac1b720e7460ec8ccf45926c78edb2047 from master
2019-12-02 08:19:18 +01:00
Mariusz Felisiak
015fab76ad [2.1.x] Fixed #30953 -- Made select_for_update() lock queryset's model when using "self" with multi-table inheritance.
Thanks Abhijeet Viswa for the report and initial patch.

Backport of 0107e3d1058f653f66032f7fd3a0bd61e96bf782 from master.
2019-12-02 08:13:13 +01:00
Sergey Fedoseev
ed50f6c424 [2.1.x] Made versionadded/versionchanged annotations without a content end with ".".
Regression in d2afa5eb2308e672b6313876856e32e2561b90f3.
Backport of 5032556483f16b0b5f182e393eb5c6548fc505be from master
2019-11-21 09:04:30 +01:00
Mariusz Felisiak
0423ea1fa8 [2.1.x] Added stub release notes for 2.1.15.
Backport of e9def97d1095efed15a109d82fe0498ebd56fa04 from master
2019-11-19 12:45:25 +01:00
Mariusz Felisiak
cfc0378224 [2.1.x] Post-release version bump. 2019-11-04 09:19:48 +01:00
Mariusz Felisiak
11f29b6e17 [2.1.x] Bumped version for 2.1.14 release. 2.1.14 2019-11-04 09:12:34 +01:00
Mariusz Felisiak
341b2aa658 [2.1.x] Added release dates for 2.1.14 and 1.11.26.
Backport of 126cfefce2b59900138f2bf1ef6ad966cddc55d4 from master
2019-11-04 08:28:19 +01:00
Louise Grandjonc
522af9d673 [2.1.x] Fixed #30826 -- Fixed crash of many JSONField lookups when one hand side is key transform.
Regression in 6c3dfba89215fc56fc27ef61829a6fff88be4abb.

Backport of 7d1bf29977bb368d7c28e7c6eb146db3b3009ae7 from master.
2019-10-11 11:57:16 +02:00
Mariusz Felisiak
608b787135 [2.1.x] Added stub release notes for 1.11.26 and 2.1.14.
Backport of 84322a29ce9b0940335f8ab3d60e55192bef1e50 from master
2019-10-02 07:56:33 +02:00
Carlton Gibson
cd0a7709f1 [2.1.x] Post-release version bump. 2019-10-01 10:25:59 +02:00
Carlton Gibson
32163d893f [2.1.x] Bumped version for 2.1.13 release. 2.1.13 2019-10-01 10:21:12 +02:00
Carlton Gibson
27e7e1c8ee [2.1.x] Added release dates for 2.1.13, and 1.11.25.
Backport of 3826aed46d7d4310c2ab6777a4f92165ca4d8d4f from master.
2019-10-01 09:00:01 +02:00
David Vaz
1556a67c65 [2.1.x] Fixed #30216 -- Doc'd that BooleanField is no longer blank=True in Django 2.1.
Backport of a6972e88547ad5a51592f2b6d5046754c4b59394 from stable/2.2.x
2019-09-27 13:02:08 +02:00
Simon Charette
db181f4b7c [2.1.x] Fixed #30769 -- Fixed a crash when filtering against a subquery JSON/HStoreField annotation.
This was a regression introduced by 7deeabc7c7526786df6894429ce89a9c4b614086
to address CVE-2019-14234.

Thanks Tim Kleinschmidt for the report and Mariusz for the tests.

Backport of 6c3dfba89215fc56fc27ef61829a6fff88be4abb from master.
2019-09-16 08:55:16 +02:00
Mariusz Felisiak
0cdd27de1a [2.1.x] Added stub release notes for 1.11.25 and 2.1.13.
Backport of bd7e0f81f8590eadcb820c976ba03c9b75bbcad6 from master
2019-09-16 07:44:19 +02:00
Mariusz Felisiak
e48e08e01b [2.1.x] Post-release version bump. 2019-09-02 09:03:12 +02:00
Mariusz Felisiak
1d1713c477 [2.1.x] Bumped version for 2.1.12 release. 2.1.12 2019-09-02 08:38:07 +02:00
Mariusz Felisiak
df853647d7 [2.1.x] Added release dates for 2.1.12 and 1.11.24.
Backport of 47f49adc11c0d39be3f41f92becc1f606c49d8ce from master.
2019-09-02 07:46:49 +02:00
Mariusz Felisiak
2a996a4a19 [2.1.x] Fixed test_json.TestQuerying.test_key_transform_expression() on Python 3.5.
Backport of 6624a3de286ccebf2dafba5a3e9b5ee91ae43cf9 from stable/2.2.x
2019-08-15 19:40:31 +02:00
Mariusz Felisiak
968b9af9b7 [2.1.x] Fixed #30672 -- Fixed crash of JSONField/HStoreField key transforms on expressions with params.
Regression in 4f5b58f5cd3c57fee9972ab074f8dc6895d8f387.

Thanks Florian Apolloner for the report and helping with tests.

Backport of 1f8382d34d54061eddc41df6994e20ee38c60907 from master.
2019-08-14 15:37:01 +02:00
Carlton Gibson
46c2856543 [2.1.x] Added CVE-2019-14235 to security release archive.
Backport of a5652eb795e896df0c0f2515201f35f9cd86b99b from master
2019-08-01 12:06:02 +02:00
Carlton Gibson
8403afd843 [2.1.x] Added CVE-2019-14234 to security release archive.
Backport of 3a6a2f5eaf74200a9591a6311fdb0ea78ee305ee from master
2019-08-01 12:05:56 +02:00
Carlton Gibson
8ffd075373 [2.1.x] Added CVE-2019-14233 to security release archive.
Backport of 9600f63885d2d240f85d59bff6acbe200f890298 from master
2019-08-01 12:05:49 +02:00
Carlton Gibson
dbecd71e43 [2.1.x] Added CVE-2019-14232 to the security release archive.
Backport of 87750787d1e464b7143f366d9485ba20fefc9c94 from master
2019-08-01 12:05:42 +02:00
Carlton Gibson
d974492c31 [2.1.x] Post-release version bump. 2019-08-01 10:53:28 +02:00
Carlton Gibson
ff9dcc0867 [2.1.x] Bumped version for 2.1.11 release. 2.1.11 2019-08-01 10:48:48 +02:00
Florian Apolloner
5d50a2e5fa [2.1.x] Fixed CVE-2019-14235 -- Fixed potential memory exhaustion in django.utils.encoding.uri_to_iri().
Thanks to Guido Vranken for initial report.
2019-07-31 12:43:32 +02:00
Mariusz Felisiak
f74b3ae362 [2.1.x] Fixed CVE-2019-14234 -- Protected JSONField/HStoreField key and index lookups against SQL injection.
Thanks to Sage M. Abdullah for the report and initial patch.
Thanks Florian Apolloner for reviews.
2019-07-31 12:43:32 +02:00
Florian Apolloner
5ff8e79114 [2.1.X] Fixed CVE-2019-14233 -- Prevented excessive HTMLParser recursion in strip_tags() when handling incomplete HTML entities.
Thanks to Guido Vranken for initial report.
2019-07-29 11:12:53 +02:00
Florian Apolloner
c23723a155 [2.1.X] Fixed CVE-2019-14232 -- Adjusted regex to avoid backtracking issues when truncating HTML.
Thanks to Guido Vranken for initial report.
2019-07-29 11:09:18 +02:00
Carlton Gibson
24eba901eb [2.1.x] Added stub release notes for security releases.
Backport of f13147c8de725eed7038941758469aeb9bd66503 from master
2019-07-25 10:54:51 +02:00
Mariusz Felisiak
765dac3d76 [2.1.x] Added CVE-2019-12781 to the security release archive.
Backport of 868cd56f058ca203419ad0886353173b74c3bcf1 from master
2019-07-01 10:21:48 +02:00
Mariusz Felisiak
fafde97fd7 [2.1.x] Post-release version bump. 2019-07-01 08:37:24 +02:00
Mariusz Felisiak
90a1cfd600 [2.1.x] Bumped version for 2.1.10 release. 2.1.10 2019-07-01 08:27:38 +02:00
Carlton Gibson
1e40f427bb [2.1.x] Fixed CVE-2019-12781 -- Made HttpRequest always trust SECURE_PROXY_SSL_HEADER if set.
An HTTP request would not be redirected to HTTPS when the
SECURE_PROXY_SSL_HEADER and SECURE_SSL_REDIRECT settings were used if
the proxy connected to Django via HTTPS.

HttpRequest.scheme will now always trust the SECURE_PROXY_SSL_HEADER if
set, rather than falling back to the request scheme when the
SECURE_PROXY_SSL_HEADER did not have the secure value.

Thanks to Gavin Wahl for the report and initial patch suggestion, and
Shai Berger for review.

Backport of 54d0f5e62f54c29a12dd96f44bacd810cbe03ac8 from master
2019-07-01 08:24:47 +02:00
Mariusz Felisiak
87be9c9626 [2.1.x] Added stub release notes for security releases.
Backport of 30b3ee9d0b33bb440f9c73d1ce9e0e7303887a9f from master
2019-07-01 07:04:03 +02:00
Mariusz Felisiak
757c226fd6 [2.1.x] Fixed GeoIPTest.test04_city() failure with the latest GeoIP2 database.
Backport of 4305fbe8b11f44ab5d6759346488026c1e9677b2 from master
2019-06-30 20:17:44 +02:00
Markus Holtermann
20968e3eae [2.1.x] Bumped minimum ESLint version to 4.18.2.
Backport of ad7b438002f1ab2a0ccb321012182991737ea84e from master.
2019-06-21 18:04:44 +02:00
Nick Pope
d58f8e4235 [2.1.x] Added CVE-2019-12308 to the security release archive.
Backport of 21b1d239125f1228e579b1ce8d94d4d5feadd2a6 from master
2019-06-03 21:46:58 +02:00
Nick Pope
8827e09944 [2.1.x] Added CVE-2019-11358 to the security release archive.
Backport of 8fb0ea55830321852a4a051a478f78e24d4f6889 from master
2019-06-03 21:46:54 +02:00
Mariusz Felisiak
73158f19f1 [2.1.x] Fixed typos in 1.11.21, 2.1.9, 2.2.2 release notes.
Backport of 100ec901aebebe56b61f101af38a228414098dd5 from master
2019-06-03 14:12:40 +02:00
Carlton Gibson
eecf5a1474 [2.1.x] Post-release version bump. 2019-06-03 12:00:09 +02:00
Carlton Gibson
60ebd195c9 [2.1.x] Bumped version for 2.1.9 release. 2.1.9 2019-06-03 11:55:22 +02:00
Carlton Gibson
95649bc085 [2.1.x] Applied jQuery patch for CVE-2019-11358.
Backport of 34ec52269ade54af31a021b12969913129571a3f from master.
2019-06-03 11:39:15 +02:00
Carlton Gibson
09186a13d9 [2.1.x] Fixed CVE-2019-12308 -- Made AdminURLFieldWidget validate URL before rendering clickable link.
Backport of deeba6d92006999fee9adfbd8be79bf0a59e8008 from master.
2019-06-03 11:37:57 +02:00