Release | June 13, 2023

Security patch for django-filer

5 minutes read

The updated release 2.2.5 is now available from our GitHub repository and PyPI.

Details

django filer did not check permissions properly for listing directories, moving files or folders, or uploading files. Effectively, a staff user without any permissions could thereby browse filer's folder tree if they knew the url. This vulnerability would expose the folder tree and the files to a staff user without permissions.

Please see the relevant commits on GitHub for more information about the vulnerability and mitigation.

Thanks to Akshar Tank for the detailed report through our security email.

As ever, we remind our users and contributors that all security reports, patches and concerns be addressed only to our security team by email, at [email protected]

Please do not use GitHub, our email lists or slack to report, address or otherwise discuss matters relating to security.

Release

django CMS 5.1.3 and 5.0.13 released

We’re pleased to announce the release of django CMS 5.1.3 and django CMS 5.0.13. Both are maintenance releases focused on fixes and improved robustness.

Community news

Inside the Work That Moves django CMS Forward

As the django CMS fellows, we have spent this year so far strengthening that foundation and making new capabilities available to developers and editors.

Tutorials

django CMS 5.1: Your CMS, Your Way — Now Easier to Set Up Than Ever

Setting up a powerful CMS shouldn’t be the hardest part of building a website. With django CMS 5.1, it no longer has to be.