All vulnerabilities

GHSA-jm5p-837g-rv8g

PyPI · wagtail

Summary

Wagtail: Improper restriction handling on Page translation API endpoint

Advisory details

Impact

A CMS user with the "submit translations" permission, could use the Admin API's "copy for translation" endpoint to copy an existing page that they do not have edit access to, allowing them to view its contents.

Patches

Patched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.3 and 8.0rc2.

Workarounds

N/A

Acknowledgements

Many thanks to tinyb0y for reporting this issue.

For more information

If you have any questions or comments about this advisory:

References