CVE-2016-9646

MEDIUM

ikiwiki < 3.20161229 - Commit Metadata Forgery via CGI::FormBuilder->field Method

Title source: llm
STIX 2.1

Description

ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572), which can be abused to lead to commit metadata forgery.

References (4)

Core 4
Core References
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2017/dsa-3760
Issue Tracking, Third Party Advisory x_refsource_confirm
https://security-tracker.debian.org/tracker/CVE-2016-9646
Vendor Advisory x_refsource_confirm
https://ikiwiki.info/security/#cve-2016-9646
Third Party Advisory mailing-list x_refsource_mlist
https://marc.info/?l=oss-security&m=148304341511854&w=2

Scores

CVSS v3 5.3
EPSS 0.0118
EPSS Percentile 63.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-287
Status published
Products (4)
debian/debian_linux 7.0
debian/debian_linux 8.0
debian/debian_linux 9.0
ikiwiki/ikiwiki < 3.20161229
Published Apr 13, 2018
Tracked Since Feb 18, 2026