Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g4mx-rm5q-vh24

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 5.4

Описание

MoinMoin Improper Access Control

security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a member of the group.

Пакеты

Наименование

moin

pip
Затронутые версииВерсия исправления

>= 1.9, < 1.9.5

1.9.5

EPSS

Процентиль: 76%
0.0099
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

ubuntu
больше 13 лет назад

security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a member of the group.

nvd
больше 13 лет назад

security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a member of the group.

debian
больше 13 лет назад

security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly h ...

EPSS

Процентиль: 76%
0.0099
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-284