Webmin 0.84 and earlier does not properly clear the HTTP_AUTHORIZATION environment variable when the web server is restarted, which makes authentication information available to all CGI programs and allows local users to gain privileges.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Webmin | Webmin | 0.5 (including) | 0.5 (including) |
Webmin | Webmin | 0.6 (including) | 0.6 (including) |
Webmin | Webmin | 0.7 (including) | 0.7 (including) |
Webmin | Webmin | 0.80 (including) | 0.80 (including) |
Webmin | Webmin | 0.83 (including) | 0.83 (including) |
Webmin | Webmin | 0.84 (including) | 0.84 (including) |