Vulnerability Name: | CVE-2012-4404 (CCN-78227) | ||||||||||||||||
Assigned: | 2012-09-03 | ||||||||||||||||
Published: | 2012-09-03 | ||||||||||||||||
Updated: | 2013-04-19 | ||||||||||||||||
Summary: | security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a member of the group. | ||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 6.0 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P) 4.4 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2012-4404 Source: CONFIRM Type: UNKNOWN http://hg.moinmo.in/moin/1.9/rev/7b9f39289e16 Source: CCN Type: MoinMoin Web Site Security Fix Announcements Source: CONFIRM Type: Vendor Advisory http://moinmo.in/SecurityFixes Source: SECUNIA Type: Vendor Advisory 50474 Source: CCN Type: SA50496 MoinMoin Virtual Group ACL Evaluation Security Issue Source: SECUNIA Type: Vendor Advisory 50496 Source: SECUNIA Type: UNKNOWN 50885 Source: DEBIAN Type: UNKNOWN DSA-2538 Source: DEBIAN Type: DSA-2538 moin -- privilege escalation Source: MLIST Type: UNKNOWN [oss-security] 20120904 CVE request: moinmoin incorrect ACL evaluation for virtual groups Source: MLIST Type: UNKNOWN [oss-security] 20120904 Re: CVE request: moinmoin incorrect ACL evaluation for virtual groups Source: CCN Type: BID-55391 MoinMoin Virtual Group ACL Evaluation Security Bypass Vulnerability Source: UBUNTU Type: UNKNOWN USN-1604-1 Source: XF Type: UNKNOWN moinmoin-acl-sec-bypass(78227) | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |