1.6.9
6 years ago
1 years ago
Known vulnerabilities in the wagtail-2fa package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
wagtail-2fa is a Django app adding two factor authentication to Wagtail. Affected versions of this package are vulnerable to Access Restriction Bypass. Any user with access to the CMS could view and delete other users 2FA devices by going to the correct path. By deleting the other users device they can disable the target users 2FA devices and potentially compromise the account if they figure out their password. How to fix Access Restriction Bypass? Upgrade | [,1.4.1) |
wagtail-2fa is a Django app adding two factor authentication to Wagtail. Affected versions of this package are vulnerable to Improper Access Control. If a malicious user gains access to someone's Wagtail login credentials, they can log into the CMS and bypass the 2FA check by changing the URL. They can then add a new device and gain full access to the CMS. How to fix Improper Access Control? Upgrade | [,1.3.0) |