Wagtail: Improper restriction handling on Pages admin API
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.3epss 0.2%
exploitation probability
0.2%top 90% of all CVEs
observed exploitation
nono source reports it
Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without sufficient access control, allowing a user with Wagtail admin access to retrieve restricted draft and live page content. This issue is fixed in versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
wagtail · wagtailReferences
https://github.com/wagtail/wagtail/commit/5608cfb714a130412f862beab53c78de02b79975https://github.com/wagtail/wagtail/commit/aef935530d5289406ca325b42747af15f3b28ac4https://github.com/wagtail/wagtail/commit/d99d2bec2b0aca46d88014416432c717240cd559https://github.com/wagtail/wagtail/commit/e2fa629b7a51ec29d59e45eead930feee0d3c4b3https://github.com/wagtail/wagtail/security/advisories/GHSA-3vrh-m9w7-v94f