Description
MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchical ACLs, which allows remote attackers to bypass intended access restrictions by requesting an item, a different vulnerability than CVE-2008-6603.
References (9)
Core 9
Core References
Patch x_refsource_confirm
http://hg.moinmo.in/moin/1.7/rev/897cdbe9e8f2
Vendor Advisory x_refsource_confirm
http://moinmo.in/SecurityFixes
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1208
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2010/dsa-2014
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/39887
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/35277
Various Sources vendor-advisory
x_refsource_ubuntu
http://ubuntu.com/usn/usn-941-1
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0600
Patch x_refsource_confirm
http://hg.moinmo.in/moin/1.8/rev/897cdbe9e8f2
Scores
EPSS
0.0300
EPSS Percentile
86.0%
Details
CWE
CWE-264
Status
published
Products (7)
moinmo/moinmoin
1.7.0
moinmo/moinmoin
1.7.1
moinmo/moinmoin
1.7.2
moinmo/moinmoin
1.8.0
moinmo/moinmoin
1.8.1
moinmo/moinmoin
1.8.2
pypi/moin
1.7.0 - 1.7.3PyPI
Published
Mar 29, 2010
Tracked Since
Feb 18, 2026