CVE Vulnerabilities

CVE-2012-4404

Published: Sep 10, 2012 | Modified: Apr 19, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

security/init.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as All, Known, or Trusted, which allows remote authenticated users with virtual group membership to be treated as a member of the group.

Affected Software

Name Vendor Start Version End Version
Moinmoin Moinmo 1.9.0 (including) 1.9.0 (including)
Moinmoin Moinmo 1.9.1 (including) 1.9.1 (including)
Moinmoin Moinmo 1.9.2 (including) 1.9.2 (including)
Moinmoin Moinmo 1.9.3 (including) 1.9.3 (including)
Moinmoin Moinmo 1.9.4 (including) 1.9.4 (including)
Moin Ubuntu devel *
Moin Ubuntu hardy *
Moin Ubuntu lucid *
Moin Ubuntu natty *
Moin Ubuntu oneiric *
Moin Ubuntu precise *
Moin Ubuntu upstream *

References