CVE Vulnerabilities

CVE-2012-4404

Published: Sep 10, 2012 | Modified: Apr 19, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

security/init.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as All, Known, or Trusted, which allows remote authenticated users with virtual group membership to be treated as a member of the group.

Affected Software

Name Vendor Start Version End Version
Moinmoin Moinmo 1.9.0 (including) 1.9.0 (including)
Moinmoin Moinmo 1.9.1 (including) 1.9.1 (including)
Moinmoin Moinmo 1.9.2 (including) 1.9.2 (including)
Moinmoin Moinmo 1.9.3 (including) 1.9.3 (including)
Moinmoin Moinmo 1.9.4 (including) 1.9.4 (including)

References