Publish Advisories

GHSA-c2g2-gx4j-rj3j
GHSA-qg5r-95m4-mjgj
GHSA-rcvg-jj3g-rj7c
GHSA-xxfm-vmcf-g33f
This commit is contained in:
advisory-database[bot]
2024-06-02 22:28:54 +00:00
parent 6b3e02f021
commit b17ff39b5b
4 changed files with 302 additions and 0 deletions
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
@@ -0,0 +1,84 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xxfm-vmcf-g33f",
"modified": "2024-06-02T22:28:28Z",
"published": "2024-06-02T22:28:28Z",
"aliases": [
"CVE-2024-35228"
],
"summary": "Improper Handling of Insufficient Permissions in `wagtail.contrib.settings`",
"details": "### Impact\nDue to an improperly applied permission check in the `wagtail.contrib.settings` module, a user with access to the Wagtail admin and knowledge of the URL of the edit view for a settings model can access and update that setting, even when they have not been granted permission over the model. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin.\n\n### Patches\nPatched versions have been released as Wagtail 6.0.5 and 6.1.2. Wagtail releases prior to 6.0 are unaffected.\n\n### Workarounds\n\nNo workaround is available.\n\n### Acknowledgements\n\nMany thanks to Victor Miti for reporting this issue.\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n* Visit Wagtail's [support channels](https://docs.wagtail.io/en/stable/support.html)\n* Email us at [security@wagtail.org](mailto:security@wagtail.org) (view our [security policy](https://github.com/wagtail/wagtail/security/policy) for more information).\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "wagtail"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "6.0.0"
},
{
"fixed": "6.0.5"
}
]
}
]
},
{
"package": {
"ecosystem": "PyPI",
"name": "wagtail"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "6.1.0"
},
{
"fixed": "6.1.2"
}
]
}
]
}
],
"references": [
{
"type": "WEB",
"url": "https://github.com/wagtail/wagtail/security/advisories/GHSA-xxfm-vmcf-g33f"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35228"
},
{
"type": "WEB",
"url": "https://github.com/wagtail/wagtail/commit/284f75a6f91f7ab18cc304d7d34f33b559ae37b1"
},
{
"type": "PACKAGE",
"url": "https://github.com/wagtail/wagtail"
}
],
"database_specific": {
"cwe_ids": [
"CWE-280"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-06-02T22:28:28Z",
"nvd_published_at": "2024-05-30T19:15:16Z"
}
}