GHSA-5jjr-gmq3-f986
Dashboard / Vulnerabilities / GHSA-5jjr-gmq3-f986
Summary: MoinMoin has improper default configuration
Details: The default configuration of `cfg.packagepages_actions_excluded` in MoinMoin before 1.8.7 does not prevent unsafe package actions, which has unspecified impact and attack vectors.
References: https://nvd.nist.gov/vuln/detail/CVE-2010-0717, https://exchange.xforce.ibmcloud.com/vulnerabilities/56595, https://github.com/moinwiki/moin, https://github.com/pypa/advisory-database/tree/main/vulns/moin/PYSEC-2010-3.yaml, https://web.archive.org/web/20140807024009/http://secunia.com/advisories/38903, http://hg.moinmo.in/moin/1.8/raw-file/1.8.7/docs/CHANGES, http://moinmo.in/MoinMoinRelease1.8, http://www.debian.org/security/2010/dsa-2014, http://www.openwall.com/lists/oss-security/2010/02/15/2, http://www.vupen.com/english/advisories/2010/0600
Affected packages
Package
Name: moin
Purl: pkg:pypi/moin
Affected ranges
Type: ECOSYSTEM
Events:
