SB2012091101 - Permissions, Privileges, and Access Controls in MoinMoin



SB2012091101 - Permissions, Privileges, and Access Controls in MoinMoin

Published: September 11, 2012 Updated: July 28, 2020

Security Bulletin ID SB2012091101
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2012-4404)

The vulnerability allows a remote #AU# to read and manipulate data.

security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a member of the group.


Remediation

Install update from vendor's website.