Access Restriction Bypass Affecting wagtail-2fa package, versions [,1.4.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (22nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-WAGTAIL2FA-560315
  • published15 Mar 2020
  • disclosed10 Mar 2020
  • creditUnknown

Introduced: 10 Mar 2020

CVE-2020-5240  (opens in a new tab)
CWE-284  (opens in a new tab)

How to fix?

Upgrade wagtail-2fa to version 1.4.1 or higher.

Overview

wagtail-2fa is a Django app adding two factor authentication to Wagtail.

Affected versions of this package are vulnerable to Access Restriction Bypass. Any user with access to the CMS could view and delete other users 2FA devices by going to the correct path. By deleting the other users device they can disable the target users 2FA devices and potentially compromise the account if they figure out their password.

References

CVSS Scores

version 3.1