kopia lustrzana https://github.com/wagtail/wagtail
Release note for 2.7.3
rodzic
6d660b0c27
commit
e6accccfff
|
@ -122,6 +122,12 @@ Changelog
|
|||
* Fix: Make sure all modal chooser search results correspond to the latest search by canceling previous requests (Esper Kuijs)
|
||||
|
||||
|
||||
2.7.3 (04.05.2020)
|
||||
~~~~~~~~~~~~~~~~~~
|
||||
|
||||
* Fix: CVE-2020-11037 - avoid potential timing attack on password-protected private pages (Thibaud Colas)
|
||||
|
||||
|
||||
2.7.2 (14.04.2020)
|
||||
~~~~~~~~~~~~~~~~~~
|
||||
|
||||
|
|
|
@ -0,0 +1,10 @@
|
|||
===========================
|
||||
Wagtail 2.7.3 release notes
|
||||
===========================
|
||||
|
||||
CVE-2020-11037: Potential timing attack on password-protected private pages
|
||||
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
This release addresses a potential timing attack on pages or documents that have been protected with a shared password through Wagtail's "Privacy" controls. This password check is performed through a character-by-character string comparison, and so an attacker who is able to measure the time taken by this check to a high degree of accuracy could potentially use timing differences to gain knowledge of the password. (This is `understood to be feasible on a local network, but not on the public internet <https://groups.google.com/d/msg/django-developers/iAaq0pvHXuA/fpUuwjK3i2wJ>`_.)
|
||||
|
||||
Many thanks to Thibaud Colas for reporting this issue.
|
|
@ -9,6 +9,7 @@ Release notes
|
|||
2.9
|
||||
2.8.1
|
||||
2.8
|
||||
2.7.3
|
||||
2.7.2
|
||||
2.7.1
|
||||
2.7
|
||||
|
|
Ładowanie…
Reference in New Issue