Vulnerability Description
_macro_Getval in wikimacro.py in MoinMoin 1.5.8 and earlier does not properly enforce ACLs, which allows remote attackers to read protected pages.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Moinmoin | Moinmoin | <= 1.5.8 |
Related Weaknesses (CWE)
References
- http://hg.moinmo.in/moin/1.5/rev/4a7de0173734
- http://moinmo.in/SecurityFixes
- http://secunia.com/advisories/29262
- http://secunia.com/advisories/29444
- http://secunia.com/advisories/30031
- http://secunia.com/advisories/33755
- http://www.debian.org/security/2008/dsa-1514
- http://www.gentoo.org/security/en/glsa/glsa-200803-27.xml
- http://www.securityfocus.com/bid/28177
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41038
- https://usn.ubuntu.com/716-1/
- https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00510.html
- https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00538.html
- http://hg.moinmo.in/moin/1.5/rev/4a7de0173734
- http://moinmo.in/SecurityFixes
FAQ
What is CVE-2008-1099?
CVE-2008-1099 is a vulnerability with a CVSS score of 5.0 (MEDIUM). _macro_Getval in wikimacro.py in MoinMoin 1.5.8 and earlier does not properly enforce ACLs, which allows remote attackers to read protected pages.
How severe is CVE-2008-1099?
CVE-2008-1099 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-1099?
Check the references section above for vendor advisories and patch information. Affected products include: Moinmoin Moinmoin.