wagtail-2fa
PyPI2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting wagtail-2fapage 1 of 1
- CVE-2019-16766HIGHCVSS 8.7EG 8.7✓ Fixed in 1.3.02019-11-29
vulnerable: 0.0.1 ... 1.2.0 (8 versions)
When using wagtail-2fa before 1.3.0, if someone gains access to someone's Wagtail login credentials, they can log into the CMS and bypass the 2FA check by changing the URL. They can then add a new device and gain full access to the CMS. Th…
- CVE-2020-5240HIGHCVSS 7.6EG 7.6✓ Fixed in 1.4.12020-03-13
vulnerable: 0.0.1 ... 1.4.0 (14 versions)
In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the correct path. The user does not require special permissions in order to do so. By deleting the other users device they…
Check whether wagtail-2fa is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for wagtail-2fa CVEs against the assets you own.
Start Free Scan →