Vulnerability Description
A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ikiwiki | Ikiwiki | < 3.20170111 |
| Debian | Debian Linux | 7.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/95420Third Party AdvisoryVDB Entry
- https://ikiwiki.info/security/#cve-2017-0356Vendor Advisory
- https://marc.info/?l=oss-security&m=148418234314276&w=2ExploitThird Party Advisory
- https://www.debian.org/security/2017/dsa-3760Third Party Advisory
- http://www.securityfocus.com/bid/95420Third Party AdvisoryVDB Entry
- https://ikiwiki.info/security/#cve-2017-0356Vendor Advisory
- https://marc.info/?l=oss-security&m=148418234314276&w=2ExploitThird Party Advisory
- https://www.debian.org/security/2017/dsa-3760Third Party Advisory
FAQ
What is CVE-2017-0356?
CVE-2017-0356 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters.
How severe is CVE-2017-0356?
CVE-2017-0356 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-0356?
Check the references section above for vendor advisories and patch information. Affected products include: Ikiwiki Ikiwiki, Debian Debian Linux.