Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wc8w-gh5m-62fv

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

MoinMoin Access Restrictions Bypassed due to improper ACL enforcement

MoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_hierarchic is set to True, which might allow remote attackers to bypass intended access restrictions, a different vulnerability than CVE-2008-1937.

Пакеты

Наименование

moin

pip
Затронутые версииВерсия исправления

< 1.6.3

1.6.3

Наименование

moin

pip
Затронутые версииВерсия исправления

= 1.7

1.7.1

EPSS

Процентиль: 44%
0.00211
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

ubuntu
больше 16 лет назад

MoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_hierarchic is set to True, which might allow remote attackers to bypass intended access restrictions, a different vulnerability than CVE-2008-1937.

redhat
больше 17 лет назад

MoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_hierarchic is set to True, which might allow remote attackers to bypass intended access restrictions, a different vulnerability than CVE-2008-1937.

nvd
больше 16 лет назад

MoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_hierarchic is set to True, which might allow remote attackers to bypass intended access restrictions, a different vulnerability than CVE-2008-1937.

debian
больше 16 лет назад

MoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_h ...

EPSS

Процентиль: 44%
0.00211
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-284