Skip to content

Commit

Permalink
Release note for 2.7.3
Browse files Browse the repository at this point in the history
  • Loading branch information
gasman committed May 4, 2020
1 parent b3698f9 commit 3f55039
Show file tree
Hide file tree
Showing 3 changed files with 17 additions and 0 deletions.
6 changes: 6 additions & 0 deletions CHANGELOG.txt
Original file line number Diff line number Diff line change
@@ -1,6 +1,12 @@
Changelog
=========

2.7.3 (04.05.2020)
~~~~~~~~~~~~~~~~~~

* Fix: CVE-2020-11037 - avoid potential timing attack on password-protected private pages (Thibaud Colas)


2.7.2 (14.04.2020)
~~~~~~~~~~~~~~~~~~

Expand Down
10 changes: 10 additions & 0 deletions docs/releases/2.7.3.rst
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
===========================
Wagtail 2.7.3 release notes
===========================

CVE-2020-11037: Potential timing attack on password-protected private pages
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

This release addresses a potential timing attack on pages or documents that have been protected with a shared password through Wagtail's "Privacy" controls. This password check is performed through a character-by-character string comparison, and so an attacker who is able to measure the time taken by this check to a high degree of accuracy could potentially use timing differences to gain knowledge of the password. (This is `understood to be feasible on a local network, but not on the public internet <https://groups.google.com/d/msg/django-developers/iAaq0pvHXuA/fpUuwjK3i2wJ>`_.)

Many thanks to Thibaud Colas for reporting this issue.
1 change: 1 addition & 0 deletions docs/releases/index.rst
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ Release notes
:maxdepth: 1

upgrading
2.7.3
2.7.2
2.7.1
2.7
Expand Down

0 comments on commit 3f55039

Please sign in to comment.