THREAT OPS › Threat News › [GHSA] GHSA-x5cx-w6p2-mxf2 (medium) — Wagtail: Improper permission handling when copying snippets
[GHSA] GHSA-x5cx-w6p2-mxf2 (medium) — Wagtail: Improper permission handling when copying snippets
GHSA-x5cx-w6p2-mxf2 Severity: medium CVE: None
Wagtail: Improper permission handling when copying snippets
### Impact A CMS user with "add" permission over a snippet model, but not "change" or "view" permission, could copy an existing snippet that they do not have access to, allowing them to view its contents.
### Patches Patched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.3 and 8.
Indicators of compromise
- https://docs.wagtail.org/en/stable/support.htmlurl
- security@wagtail.orgemail
Original source: https://github.com/advisories/GHSA-x5cx-w6p2-mxf2