1. ===========================
    
  2. Django 2.2.20 release notes
    
  3. ===========================
    
  4. 
    
  5. *April 6, 2021*
    
  6. 
    
  7. Django 2.2.20 fixes a security issue with severity "low" in 2.2.19.
    
  8. 
    
  9. CVE-2021-28658: Potential directory-traversal via uploaded files
    
  10. ================================================================
    
  11. 
    
  12. ``MultiPartParser`` allowed directory-traversal via uploaded files with
    
  13. suitably crafted file names.
    
  14. 
    
  15. Built-in upload handlers were not affected by this vulnerability.