1. ============================
    
  2. Django 1.11.28 release notes
    
  3. ============================
    
  4. 
    
  5. *February 3, 2020*
    
  6. 
    
  7. Django 1.11.28 fixes a security issue in 1.11.27.
    
  8. 
    
  9. CVE-2020-7471: Potential SQL injection via ``StringAgg(delimiter)``
    
  10. ===================================================================
    
  11. 
    
  12. :class:`~django.contrib.postgres.aggregates.StringAgg` aggregation function was
    
  13. subject to SQL injection, using a suitably crafted ``delimiter``.