MEDIUM · 6.0

CVE-2012-4404

security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users w...

Vulnerability Description

security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a member of the group.

CVSS Score

6.0

MEDIUM

AV:N/AC:M/Au:S/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
MoinmoMoinmoin1.9.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-4404?

CVE-2012-4404 is a vulnerability with a CVSS score of 6.0 (MEDIUM). security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users w...

How severe is CVE-2012-4404?

CVE-2012-4404 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-4404?

Check the references section above for vendor advisories and patch information. Affected products include: Moinmo Moinmoin.