wagtail@8.0rc1

A Django content management system.

  • latest version

    8.0

  • latest non vulnerable version

  • first published

    12 years ago

  • latest version published

    16 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the wagtail package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Improper Handling of Insufficient Permissions or Privileges

    wagtail is an open source content management system built on Django.

    Affected versions of this package are vulnerable to Improper Handling of Insufficient Permissions or Privileges in the copy for snippets. An attacker can gain unauthorized access to the contents of existing snippets by exploiting insufficient permission checks when copying snippets.

    How to fix Improper Handling of Insufficient Permissions or Privileges?

    Upgrade wagtail to version 7.0.9, 7.3.4, 7.4.3, 8.0rc2 or higher.

    [,7.0.9)[7.1rc1,7.3.4)[7.4rc1,7.4.3)[8.0rc1,8.0rc2)
    • H
    Improper Handling of Insufficient Permissions or Privileges

    wagtail is an open source content management system built on Django.

    Affected versions of this package are vulnerable to Improper Handling of Insufficient Permissions or Privileges via the copy for translation endpoint in the Admin API. An attacker can access the contents of pages they do not have edit permissions for by submitting translation requests through this endpoint.

    How to fix Improper Handling of Insufficient Permissions or Privileges?

    Upgrade wagtail to version 7.0.9, 7.3.4, 7.4.3, 8.0rc2 or higher.

    [,7.0.9)[7.1rc1,7.3.4)[7.4rc1,7.4.3)[8.0rc1,8.0rc2)
    • M
    Improper Handling of Insufficient Permissions or Privileges

    wagtail is an open source content management system built on Django.

    Affected versions of this package are vulnerable to Improper Handling of Insufficient Permissions or Privileges via the API V2. An attacker can access filenames and names of documents and images in descendant collections of private collections by querying the API without proper authentication.

    How to fix Improper Handling of Insufficient Permissions or Privileges?

    Upgrade wagtail to version 7.0.9, 7.3.4, 7.4.3, 8.0rc2 or higher.

    [,7.0.9)[7.1rc1,7.3.4)[7.4rc1,7.4.3)[8.0rc1,8.0rc2)
    • M
    Improper Handling of Insufficient Permissions or Privileges

    wagtail is an open source content management system built on Django.

    Affected versions of this package are vulnerable to Improper Handling of Insufficient Permissions or Privileges in the document retrieval. An attacker can confirm the existence of a document with a known SHA1 hash by sending crafted HTTP headers to the document endpoint, even without proper permissions or knowledge of the filename.

    How to fix Improper Handling of Insufficient Permissions or Privileges?

    Upgrade wagtail to version 7.0.9, 7.3.4, 7.4.3, 8.0rc2 or higher.

    [,7.0.9)[7.1rc1,7.3.4)[7.4rc1,7.4.3)[8.0rc1,8.0rc2)
    • M
    Improper Handling of Insufficient Permissions or Privileges

    wagtail is an open source content management system built on Django.

    Affected versions of this package are vulnerable to Improper Handling of Insufficient Permissions or Privileges via the PagesAdminAPIViewSet class. An attacker can access sensitive page field contents by sending authenticated API requests to endpoints that expose fields declared in api_fields.

    Note: This is only exploitable if the attacker has access to the Wagtail admin interface.

    How to fix Improper Handling of Insufficient Permissions or Privileges?

    Upgrade wagtail to version 7.0.9, 7.3.4, 7.4.3, 8.0rc2 or higher.

    [,7.0.9)[7.1rc1,7.3.4)[7.4rc1,7.4.3)[8.0rc1,8.0rc2)