You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Overview
wagtail is an open source content management system built on Django.
Affected versions of this package are vulnerable to Information Exposure. When notifications for new replies in comment threads are sent, they are sent to all users who have replied or commented anywhere on the site, rather than only in the relevant threads. This means that a user could listen in to new comment replies on pages they have not had editing access to, as long as they have left a comment or reply somewhere on the site.
Summary
Introduced through
[email protected]
Fixed in
[email protected]
Overview
wagtail is an open source content management system built on Django.
Affected versions of this package are vulnerable to Information Exposure. When notifications for new replies in comment threads are sent, they are sent to all users who have replied or commented anywhere on the site, rather than only in the relevant threads. This means that a user could listen in to new comment replies on pages they have not had editing access to, as long as they have left a comment or reply somewhere on the site.
Detailed paths and remediation
Introduced through: [email protected] › [email protected]
Fix: Upgrade wagtail to version 2.15.2
The text was updated successfully, but these errors were encountered: