CVE-2012-4404
Summary
| CVE | CVE-2012-4404 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-09-10 22:55:05 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a member of the group. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - CVE request: moinmoin incorrect ACL evaluation for virtual groups | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| USN-1604-1: MoinMoin vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| moin/1.9: changeset 5870:7b9f39289e16 | af854a3a-2127-422b-91ae-364da2661108 | hg.moinmo.in | |
| SecurityFixes - MoinMoin | af854a3a-2127-422b-91ae-364da2661108 | moinmo.in | Vendor Advisory |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Debian -- Security Information -- DSA-2538-1 moin | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| oss-security - Re: CVE request: moinmoin incorrect ACL evaluation for virtual groups | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.