GHSA-8634-mr4j-r72c: Medium severity pip/wagtail vulnerability
Impact A low-level user with the "Can submit translation" permission can create translations for any page, including those they do not have permissions for.
Patches Patched versions have been released as Wagtail 7.0.8, 7.3.3, 7.4.2.
Workarounds N/A
Acknowledgements
Many thanks to @devansh3008 and @alanturing881 for reporting this issue.
For more information
If you have any questions or comments about this advisory:
Visit Wagtail's support channels Email us at security@wagtail.org (view our security policy for more information).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/wagtailto a version that resolves this vulnerability.Fixed in 7.4.2 - Upgrade
Upgrade
pip/wagtailto a version that resolves this vulnerability.Fixed in 7.3.3 - Upgrade
Upgrade
pip/wagtailto a version that resolves this vulnerability.Fixed in 7.0.8 - Upgrade
Upgrade
wagtailto a version that resolves this vulnerability.Fixed in 7.0.8 - Upgrade
Upgrade
wagtailto a version that resolves this vulnerability.Fixed in 7.3.3 - Upgrade
Upgrade
wagtailto a version that resolves this vulnerability.Fixed in 7.4.2
Event History
Frequently Asked Questions
Who can exploit this issue?
A low-level user who has the "Can submit translation" permission can exploit it. The user does not need permission to access the pages for which they create translations.
Which releases contain fixes?
Fixes were released in Wagtail 7.0.8, 7.3.3, and 7.4.2.
Is there a workaround when upgrading is not immediately possible?
No workaround is listed. Restricting the "Can submit translation" permission to trusted users may reduce exposure, but this is not identified as an official workaround in the advisory.