CVE-2012-4404 β Improper Access Control in Moinmoin
Severity
6.0MEDIUMNVD
EPSS
1.0%
top 23.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 10
Latest updateMay 17
Description
security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a member of the group.
CVSS vector
AV:N/AC:M/C:P/I:P/A:PExploitability: 6.8 | Impact: 6.4
Affected Packages1 packages
π΄Vulnerability Details
3πVendor Advisories
1π¬Community
3BugzillaβΆ
CVE-2012-4404 moin: Improper ACL rules enforcement due to a bug in the way virtual groups were handled previously during ACL evaluation [fedora-all]β2012-09-05
BugzillaβΆ
CVE-2012-4404 moin: Improper ACL rules enforcement due to a bug in the way virtual groups were handled previously during ACL evaluationβ2012-09-05
BugzillaβΆ
CVE-2012-4404 moin: Improper ACL rules enforcement due to a bug in the way virtual groups were handled previously during ACL evaluation [epel-5]β2012-09-05