QID 983119
QID 983119: Python (pip) Security Update for wagtail-2fa (GHSA-9gjv-6qq6-v7qm)
Security update has been released for wagtail-2fa to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Any user with access to the CMS can view and delete other users' 2FA devices by going to the correct path. The user does not require special permissions in order to do so. By deleting the other user's device they can disable the target user's 2FA devices and potentially compromise the account if they figure out their password.
Solution
The problem has been patched in version 1.4.1.Workaround:
There is no workaround for this issue.
There is no workaround for this issue.
Vendor References
- GHSA-9gjv-6qq6-v7qm -
github.com/advisories/GHSA-9gjv-6qq6-v7qm
CVEs related to QID 983119
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9gjv-6qq6-v7qm | wagtail-2fa |
|