CVE-2012-4404

MoinMoin 1.9-1.9.4 - Authenticated Group Membership Bypass via Virtual Group Names

Title source: llm
STIX 2.1

Description

security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a member of the group.

References (9)

Core 9
Core References
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1604-1
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/50496
Vendor Advisory x_refsource_confirm
http://moinmo.in/SecurityFixes
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2012/dsa-2538
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/09/04/4
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/50885
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/50474
Various Sources x_refsource_confirm
http://hg.moinmo.in/moin/1.9/rev/7b9f39289e16
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/09/05/2

Scores

EPSS 0.0209
EPSS Percentile 79.7%

Details

CWE
CWE-264
Status published
Products (6)
moinmo/moinmoin 1.9.0
moinmo/moinmoin 1.9.1
moinmo/moinmoin 1.9.2
moinmo/moinmoin 1.9.3
moinmo/moinmoin 1.9.4
pypi/moin 1.9 - 1.9.5PyPI
Published Sep 10, 2012
Tracked Since Feb 18, 2026