Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-876c-qmcf-cxv6

Опубликовано: 02 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

MoinMoin Exposure of Sensitive Disclosure when GATEWAY_INTERFACE variable is set

MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vectors.

Пакеты

Наименование

moin

pip
Затронутые версииВерсия исправления

>= 1.9, < 1.9.1

1.9.1

EPSS

Процентиль: 73%
0.00765
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

ubuntu
почти 16 лет назад

MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vectors.

redhat
почти 16 лет назад

MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vectors.

nvd
почти 16 лет назад

MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vectors.

debian
почти 16 лет назад

MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of th ...

EPSS

Процентиль: 73%
0.00765
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-200