Skip to content

Commit

Permalink
Add 5.0.5 release note page
Browse files Browse the repository at this point in the history
  • Loading branch information
gasman committed Oct 19, 2023
1 parent 664f2e9 commit 429dec0
Showing 1 changed file with 18 additions and 0 deletions.
18 changes: 18 additions & 0 deletions docs/releases/5.0.5.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
# Wagtail 5.0.5 release notes

_October 19, 2023_

```{contents}
---
local:
depth: 1
---
```

## What's new

### CVE-2023-45809: Disclosure of user names via admin bulk action views

This release addresses an information disclosure vulnerability in the Wagtail admin interface. A user with a limited-permission editor account for the Wagtail admin can make a direct URL request to the admin view that handles bulk actions on user accounts. While authentication rules prevent the user from making any changes, the error message discloses the display names of user accounts, and by modifying URL parameters, the user can retrieve the display name for any user. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin.

Many thanks to quyenheu for reporting this issue. For further details, please see [the CVE-2023-45809 security advisory](https://github.com/wagtail/wagtail/security/advisories/GHSA-fc75-58r8-rm3h).

0 comments on commit 429dec0

Please sign in to comment.