GHSA-jm5p-837g-rv8g: Medium severity pip/wagtail vulnerability
Impact A CMS user with the "submit translations" permission, could use the Admin API's "copy for translation" endpoint to copy an existing page that they do not have edit access to, allowing them to view its contents.
Patches Patched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.3 and 8.0rc2.
Workarounds N/A
Acknowledgements Many thanks to tinyb0y for reporting this issue.
For more information If you have any questions or comments about this advisory:
Visit Wagtail's support channels Email us at security@wagtail.org (view our security policy for more information).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/wagtailto a version that resolves this vulnerability.Fixed in 8.0rc2 - Upgrade
Upgrade
pip/wagtailto a version that resolves this vulnerability.Fixed in 7.4.3 - Upgrade
Upgrade
pip/wagtailto a version that resolves this vulnerability.Fixed in 7.3.4 - Upgrade
Upgrade
pip/wagtailto a version that resolves this vulnerability.Fixed in 7.0.9 - Upgrade
Upgrade
wagtailto a version that resolves this vulnerability.Fixed in 7.0.9 - Upgrade
Upgrade
wagtailto a version that resolves this vulnerability.Fixed in 7.3.4 - Upgrade
Upgrade
wagtailto a version that resolves this vulnerability.Fixed in 7.4.3 - Upgrade
Upgrade
wagtailto a version that resolves this vulnerability.Fixed in 8.0rc2
Event History
Frequently Asked Questions
Which users should be considered capable of triggering this issue?
Any CMS user granted the "submit translations" permission should be considered capable of accessing content through the affected Admin API endpoint, including pages for which they do not have edit access.
Which Wagtail releases include the fix?
Patched releases are Wagtail 7.0.9, 7.3.4, 7.4.3, and 8.0rc2.
What mitigation is available if upgrading cannot be done immediately?
No workaround is listed. Review and restrict the "submit translations" permission to trusted users until a patched release can be deployed.