security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle...
Vulnerability Description
security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a member of the group.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-4404
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.ubuntu.com/usn/USN-1604-1
- http://secunia.com/advisories/50496
- http://moinmo.in/SecurityFixes
- http://www.debian.org/security/2012/dsa-2538
- http://www.openwall.com/lists/oss-security/2012/09/04/4
- http://secunia.com/advisories/50885
- http://secunia.com/advisories/50474
- http://hg.moinmo.in/moin/1.9/rev/7b9f39289e16
- http://www.openwall.com/lists/oss-security/2012/09/05/2
More from moinmo
View All →Affected Vendor
moinmo
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.