PYSEC-2010-13
Dashboard / Vulnerabilities / PYSEC-2010-13
PYSEC-2010-13
Summary:
Details: MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchical ACLs, which allows remote attackers to bypass intended access restrictions by requesting an item, a different vulnerability than CVE-2008-6603.
References: http://www.vupen.com/english/advisories/2010/0600, http://moinmo.in/SecurityFixes, http://www.debian.org/security/2010/dsa-2014, http://hg.moinmo.in/moin/1.8/rev/897cdbe9e8f2, http://hg.moinmo.in/moin/1.7/rev/897cdbe9e8f2, http://www.securityfocus.com/bid/35277, http://secunia.com/advisories/39887, http://www.vupen.com/english/advisories/2010/1208, http://ubuntu.com/usn/usn-941-1, https://github.com/advisories/GHSA-jj23-fj2v-m872
Affected packages
Package
Name: moin
Purl: pkg:pypi/moin
Affected ranges
Type: ECOSYSTEM
Events:
