MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vectors.
{
"nvd_published_at": "2010-02-26T19:30:00Z",
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-04-01T19:18:30Z",
"cwe_ids": [
"CWE-200"
]
}