1.6.9
6 years ago
1 years ago
Known vulnerabilities in the wagtail-2fa package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
wagtail-2fa is a Django app adding two factor authentication to Wagtail. Affected versions of this package are vulnerable to Access Restriction Bypass. Any user with access to the CMS could view and delete other users 2FA devices by going to the correct path. By deleting the other users device they can disable the target users 2FA devices and potentially compromise the account if they figure out their password. How to fix Access Restriction Bypass? Upgrade | [,1.4.1) |