2 ms·
You're right, thanks for pointing this out. Although (as jacobian mentions) Django's exposure in general to these attacks was quite limited, we still shouldn't
by _carljm 14y ago
You're right, thanks for pointing this out. Although (as jacobian mentions) Django's exposure in general to these attacks was quite limited, we still shouldn't describe these XML vulnerabilities as DoS-only.
I'm working on updates to the release announcement and release notes for 1.3.6 and 1.4.4 to make this clearer.
- _carljm 14y agoThe advisory and release notes are now fixed to not describe the XML vulnerabilities as DoS.