PT-2010-2420 · Moinmoin · Moinmoin

Published

2010-02-26

·

Updated

2022-05-02

·

CVE-2010-0668

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MoinMoin versions 1.5.x through 1.7.x MoinMoin versions 1.8.x before 1.8.7 MoinMoin versions 1.9.x before 1.9.2
Description The issue is related to certain configurations, including a non-empty superuser list, the xmlrpc action enabled, the SyncPages action enabled, or OpenID configured. The impact and attack vectors of this issue are unknown.
Recommendations For MoinMoin versions 1.5.x through 1.7.x, update to a version outside of this range to resolve the issue. For MoinMoin versions 1.8.x before 1.8.7, update to version 1.8.7 or later. For MoinMoin versions 1.9.x before 1.9.2, update to version 1.9.2 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2010-0668
DSA-2014-1
GHSA-574F-MH6M-C6QM
PYSEC-2010-15

Affected Products

Moinmoin