Release note for 2.7.3

pull/6009/head
Matt Westcott 2020-05-04 10:28:39 +01:00
rodzic 6d660b0c27
commit e6accccfff
3 zmienionych plików z 17 dodań i 0 usunięć

Wyświetl plik

@ -122,6 +122,12 @@ Changelog
* Fix: Make sure all modal chooser search results correspond to the latest search by canceling previous requests (Esper Kuijs)
2.7.3 (04.05.2020)
~~~~~~~~~~~~~~~~~~
* Fix: CVE-2020-11037 - avoid potential timing attack on password-protected private pages (Thibaud Colas)
2.7.2 (14.04.2020)
~~~~~~~~~~~~~~~~~~

Wyświetl plik

@ -0,0 +1,10 @@
===========================
Wagtail 2.7.3 release notes
===========================
CVE-2020-11037: Potential timing attack on password-protected private pages
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
This release addresses a potential timing attack on pages or documents that have been protected with a shared password through Wagtail's "Privacy" controls. This password check is performed through a character-by-character string comparison, and so an attacker who is able to measure the time taken by this check to a high degree of accuracy could potentially use timing differences to gain knowledge of the password. (This is `understood to be feasible on a local network, but not on the public internet <https://groups.google.com/d/msg/django-developers/iAaq0pvHXuA/fpUuwjK3i2wJ>`_.)
Many thanks to Thibaud Colas for reporting this issue.

Wyświetl plik

@ -9,6 +9,7 @@ Release notes
2.9
2.8.1
2.8
2.7.3
2.7.2
2.7.1
2.7