Vulnerability Name: | CVE-2009-4762 (CCN-57403) | ||||||||
Assigned: | 2010-02-25 | ||||||||
Published: | 2010-02-25 | ||||||||
Updated: | 2010-05-27 | ||||||||
Summary: | MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchical ACLs, which allows remote attackers to bypass intended access restrictions by requesting an item, a different vulnerability than CVE-2008-6603. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-4762 Source: CONFIRM Type: Patch http://hg.moinmo.in/moin/1.7/rev/897cdbe9e8f2 Source: CONFIRM Type: Patch http://hg.moinmo.in/moin/1.8/rev/897cdbe9e8f2 Source: CCN Type: MoinMoin Web site Security Fix Announcements: moin 1.9.2 Source: CONFIRM Type: Vendor Advisory http://moinmo.in/SecurityFixes Source: SECUNIA Type: UNKNOWN 39887 Source: UBUNTU Type: UNKNOWN USN-941-1 Source: DEBIAN Type: UNKNOWN DSA-2014 Source: DEBIAN Type: DSA-2014 moin -- several vulnerabilities Source: BID Type: UNKNOWN 35277 Source: CCN Type: BID-35277 MoinMoin Hierarchical ACL Security Bypass Vulnerability Source: CCN Type: USN-941-1 MoinMoin vulnerability Source: VUPEN Type: Vendor Advisory ADV-2010-0600 Source: VUPEN Type: UNKNOWN ADV-2010-1208 Source: XF Type: UNKNOWN moinmoin-item-security-bypass(57403) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |