CVE-2012-4404

security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a member of the group.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:moinmo:moinmoin:1.9.0:*:*:*:*:*:*:*
cpe:2.3:a:moinmo:moinmoin:1.9.1:*:*:*:*:*:*:*
cpe:2.3:a:moinmo:moinmoin:1.9.2:*:*:*:*:*:*:*
cpe:2.3:a:moinmo:moinmoin:1.9.3:*:*:*:*:*:*:*
cpe:2.3:a:moinmo:moinmoin:1.9.4:*:*:*:*:*:*:*

Information

Published : 2012-09-10 15:55

Updated : 2013-04-18 20:24


NVD link : CVE-2012-4404

Mitre link : CVE-2012-4404


JSON object : View

CWE
CWE-264

Permissions, Privileges, and Access Controls

Advertisement

dedicated server usa

Products Affected

moinmo

  • moinmoin