CVE-2009-4762
Summary
| CVE | CVE-2009-4762 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-03-29 20:30:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchical ACLs, which allows remote attackers to bypass intended access restrictions by requesting an item, a different vulnerability than CVE-2008-6603. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Moinmo | Moinmoin | 1.7.0 | All | All | All |
| Application | Moinmo | Moinmoin | 1.7.1 | All | All | All |
| Application | Moinmo | Moinmoin | 1.7.2 | All | All | All |
| Application | Moinmo | Moinmoin | 1.8.0 | All | All | All |
| Application | Moinmo | Moinmoin | 1.8.1 | All | All | All |
| Application | Moinmo | Moinmoin | 1.8.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Debian -- Security Information -- DSA-2014-1 moin | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| USN-941-1: MoinMoin vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | ubuntu.com | |
| Ubuntu update for moin - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SecurityFixes - MoinMoin | af854a3a-2127-422b-91ae-364da2661108 | moinmo.in | Vendor Advisory |
| MoinMoin Hierarchical ACL Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| 502 Bad Gateway | af854a3a-2127-422b-91ae-364da2661108 | hg.moinmo.in | Patch |
| Webmail | OVH- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| 502 Bad Gateway | af854a3a-2127-422b-91ae-364da2661108 | hg.moinmo.in | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.