Safety vulnerability ID: 37860
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Wagtail-2fa version 1.4.1 includes a fix for CVE-2020-5240: In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the correct path. The user does not require special permissions in order to do so. By deleting the other users device they can disable the target users 2FA devices and potentially compromise the account if they figure out their password.
Latest version: 1.6.9
Two factor authentication for Wagtail
=================
- Resolve possible vulnerability where users could delete
other users' 2FA devices
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application