The fix for ikiwiki for CVE-2016-10026 was incomplete resulting in editing restriction bypass for git revert when using git versions older than 2.8.0. This has been fixed in 3.20161229.
References
Link | Resource |
---|---|
https://security-tracker.debian.org/tracker/CVE-2016-9645 | Third Party Advisory |
https://ikiwiki.info/security/#cve-2016-9645 | Vendor Advisory |
https://marc.info/?l=oss-security&m=148304341511854&w=2 | Third Party Advisory |
Configurations
Information
Published : 2018-04-10 15:29
Updated : 2018-05-22 08:57
NVD link : CVE-2016-9645
Mitre link : CVE-2016-9645
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
ikiwiki
- ikiwiki