MoinMoin Improper Access Control vulnerability
High severity
GitHub Reviewed
Published
May 2, 2022
to the GitHub Advisory Database
•
Updated Oct 1, 2024
Package
Affected versions
>= 1.7.0, < 1.7.3
>= 1.8.0, < 1.8.3
Patched versions
1.7.3
1.8.3
Description
Published by the National Vulnerability Database
Mar 29, 2010
Published to the GitHub Advisory Database
May 2, 2022
Reviewed
Apr 29, 2024
Last updated
Oct 1, 2024
MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchical ACLs, which allows remote attackers to bypass intended access restrictions by requesting an item, a different vulnerability than CVE-2008-6603.
References