Описание
MoinMoin Exposure of Sensitive Disclosure when GATEWAY_INTERFACE variable is set
MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vectors.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2010-0667
- https://github.com/pypa/advisory-database/tree/main/vulns/moin/PYSEC-2010-14.yaml
- http://hg.moinmo.in/moin/1.9/raw-file/1.9.1/docs/CHANGES
- http://hg.moinmo.in/moin/1.9/rev/04afdde50094
- http://hg.moinmo.in/moin/1.9/rev/9d8e7ce3c3a2
- http://marc.info/?l=oss-security&m=126625972814888&w=2
- http://marc.info/?l=oss-security&m=126676896601156&w=2
- http://moinmo.in/MoinMoinChat/Logs/moin-dev/2010-01-18
- http://moinmo.in/SecurityFixes
- http://www.openwall.com/lists/oss-security/2010/01/21/6
- http://www.openwall.com/lists/oss-security/2010/02/15/2
Пакеты
moin
>= 1.9, < 1.9.1
1.9.1
Связанные уязвимости
MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vectors.
MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vectors.
MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vectors.
MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of th ...