VulnerabilityModified
CVE-2012-4404
security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a…
MEDIUM 6.0EPSS 2.11%
Does this matter?
Lower severity and a low EPSS score (2.11%). Track it; it rarely justifies an emergency change on its own.
Description
security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a member of the group.
- CVSS 2.0
- 6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
- EPSS
- 2.11% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- moinmo/moinmoin
- Source
- secalert@redhat.com
References
- http://hg.moinmo.in/moin/1.9/rev/7b9f39289e16
- http://moinmo.in/SecurityFixesVendor Advisory
- http://secunia.com/advisories/50474Vendor Advisory
- http://secunia.com/advisories/50496Vendor Advisory
- http://secunia.com/advisories/50885
- http://www.debian.org/security/2012/dsa-2538
- http://www.openwall.com/lists/oss-security/2012/09/04/4
- http://www.openwall.com/lists/oss-security/2012/09/05/2
- http://www.ubuntu.com/usn/USN-1604-1
- http://hg.moinmo.in/moin/1.9/rev/7b9f39289e16
- http://moinmo.in/SecurityFixesVendor Advisory
- http://secunia.com/advisories/50474Vendor Advisory
- http://secunia.com/advisories/50496Vendor Advisory
- http://secunia.com/advisories/50885
- http://www.debian.org/security/2012/dsa-2538
- http://www.openwall.com/lists/oss-security/2012/09/04/4
- http://www.openwall.com/lists/oss-security/2012/09/05/2
- http://www.ubuntu.com/usn/USN-1604-1
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.