GHSA-g4mx-rm5q-vh24

Suggest an improvement
Source
https://github.com/advisories/GHSA-g4mx-rm5q-vh24
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-g4mx-rm5q-vh24/GHSA-g4mx-rm5q-vh24.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-g4mx-rm5q-vh24
Aliases
Published
2022-05-17T05:11:14Z
Modified
2024-09-26T15:42:48.508395Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
MoinMoin Improper Access Control
Details

security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a member of the group.

Database specific
{
    "nvd_published_at": "2012-09-10T22:55:00Z",
    "cwe_ids": [
        "CWE-284"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-05-01T10:48:28Z"
}
References

Affected packages

PyPI / moin

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.9
Fixed
1.9.5

Affected versions

1.*

1.9.0
1.9.1
1.9.2
1.9.3
1.9.4