CVE-2020-11037

Severity CVSS v4.0:
Pending analysis
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
30/04/2020
Last modified:
19/11/2024

Description

In Wagtail before versions 2.7.3 and 2.8.2, a potential timing attack exists on pages or documents that have been protected with a shared password through Wagtail&amp;#39;s "Privacy" controls. This password check is performed through a character-by-character string comparison, and so an attacker who is able to measure the time taken by this check to a high degree of accuracy could potentially use timing differences to gain knowledge of the password. This is [understood to be feasible on a local network, but not on the public internet](https://groups.google.com/d/msg/django-developers/iAaq0pvHXuA/fpUuwjK3i2wJ).<br /> <br /> Privacy settings that restrict access to pages/documents on a per-user or per-group basis (as opposed to a shared password) are unaffected by this vulnerability.<br /> <br /> This has been patched in 2.7.3, 2.8.2, 2.9.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:torchbox:wagtail:*:*:*:*:lts:*:*:* 2.7 (including) 2.7.3 (excluding)
cpe:2.3:a:torchbox:wagtail:*:*:*:*:*:*:*:* 2.8 (including) 2.8.2 (excluding)