Vulnerability Name:

CVE-2012-4404 (CCN-78227)

Assigned:2012-09-03
Published:2012-09-03
Updated:2013-04-19
Summary:security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a member of the group.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:6.0 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P)
4.4 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-264
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2012-4404

Source: CONFIRM
Type: UNKNOWN
http://hg.moinmo.in/moin/1.9/rev/7b9f39289e16

Source: CCN
Type: MoinMoin Web Site
Security Fix Announcements

Source: CONFIRM
Type: Vendor Advisory
http://moinmo.in/SecurityFixes

Source: SECUNIA
Type: Vendor Advisory
50474

Source: CCN
Type: SA50496
MoinMoin Virtual Group ACL Evaluation Security Issue

Source: SECUNIA
Type: Vendor Advisory
50496

Source: SECUNIA
Type: UNKNOWN
50885

Source: DEBIAN
Type: UNKNOWN
DSA-2538

Source: DEBIAN
Type: DSA-2538
moin -- privilege escalation

Source: MLIST
Type: UNKNOWN
[oss-security] 20120904 CVE request: moinmoin incorrect ACL evaluation for virtual groups

Source: MLIST
Type: UNKNOWN
[oss-security] 20120904 Re: CVE request: moinmoin incorrect ACL evaluation for virtual groups

Source: CCN
Type: BID-55391
MoinMoin Virtual Group ACL Evaluation Security Bypass Vulnerability

Source: UBUNTU
Type: UNKNOWN
USN-1604-1

Source: XF
Type: UNKNOWN
moinmoin-acl-sec-bypass(78227)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:moinmo:moinmoin:1.9.0:*:*:*:*:*:*:*
  • OR cpe:/a:moinmo:moinmoin:1.9.1:*:*:*:*:*:*:*
  • OR cpe:/a:moinmo:moinmoin:1.9.2:*:*:*:*:*:*:*
  • OR cpe:/a:moinmo:moinmoin:1.9.3:*:*:*:*:*:*:*
  • OR cpe:/a:moinmo:moinmoin:1.9.4:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:moinmoin:moinmoin:1.7.0:*:*:*:*:*:*:*
  • OR cpe:/a:moinmoin:moinmoin:1.7.1:*:*:*:*:*:*:*
  • OR cpe:/a:moinmoin:moinmoin:1.7.2:*:*:*:*:*:*:*
  • OR cpe:/a:moinmoin:moinmoin:1.8.0:*:*:*:*:*:*:*
  • OR cpe:/a:moinmoin:moinmoin:1.8.1:*:*:*:*:*:*:*
  • OR cpe:/a:moinmoin:moinmoin:1.8.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:17640
    P
    USN-1604-1 -- moin vulnerabilities
    2014-06-30
    oval:org.mitre.oval:def:17914
    P
    DSA-2538-1 moin - privilege escalation
    2014-06-23
    oval:com.ubuntu.precise:def:20124404000
    V
    CVE-2012-4404 on Ubuntu 12.04 LTS (precise) - medium.
    2012-09-10
    BACK
    moinmo moinmoin 1.9.0
    moinmo moinmoin 1.9.1
    moinmo moinmoin 1.9.2
    moinmo moinmoin 1.9.3
    moinmo moinmoin 1.9.4
    moinmoin moinmoin 1.7.0
    moinmoin moinmoin 1.7.1
    moinmoin moinmoin 1.7.2
    moinmoin moinmoin 1.8.0
    moinmoin moinmoin 1.8.1
    moinmoin moinmoin 1.8.2