1. ===========================
    
  2. Django 2.2.21 release notes
    
  3. ===========================
    
  4. 
    
  5. *May 4, 2021*
    
  6. 
    
  7. Django 2.2.21 fixes a security issue in 2.2.20.
    
  8. 
    
  9. CVE-2021-31542: Potential directory-traversal via uploaded files
    
  10. ================================================================
    
  11. 
    
  12. ``MultiPartParser``, ``UploadedFile``, and ``FieldFile`` allowed
    
  13. directory-traversal via uploaded files with suitably crafted file names.
    
  14. 
    
  15. In order to mitigate this risk, stricter basename and path sanitation is now
    
  16. applied.