Release | April 26, 2017

django CMS security updates

Security releases for django CMS versions 3.4 and 3.3 address medium-level vulnerabilities. We recommend updating to version 3.4.3 or 3.3.4.

5 minutes read

These updates prevent:

  • a potential escalation of privileges through a django CMS page's Advanced Settings.
  • a potential phishing attack using redirects from the login form

The updated releases are now available from our GitHub repository and PyPI.

Divio Cloud users can update their django CMS installations via the control panel.

Please see the notes on GitHub for more details.

Thanks to Anthony Steinhauser and Mark Walker for the reports.

As ever, we remind our users and contributors that all security reports, patches and concerns be addressed only to our security team by email, at [email protected].

Please do not use GitHub, our email lists or IRC to report, address or otherwise discuss matters relating to security.

django CMS SLAs for critical applications

Do you use django CMS in a critically-important application? Please contact Divio for details of SLAs, that will give you access to patches and information about vulnerabilities before disclosures or releases are made public.

Enterprise Services

Release

django CMS 5.1.3 and 5.0.13 released

We’re pleased to announce the release of django CMS 5.1.3 and django CMS 5.0.13. Both are maintenance releases focused on fixes and improved robustness.

Community news

Inside the Work That Moves django CMS Forward

As the django CMS fellows, we have spent this year so far strengthening that foundation and making new capabilities available to developers and editors.

Tutorials

django CMS 5.1: Your CMS, Your Way — Now Easier to Set Up Than Ever

Setting up a powerful CMS shouldn’t be the hardest part of building a website. With django CMS 5.1, it no longer has to be.