MoinMoin Group Name Privilege Escalation Vulnerability
BID:10568
Info
MoinMoin Group Name Privilege Escalation Vulnerability
| Bugtraq ID: | 10568 |
| Class: | Access Validation Error |
| CVE: |
CVE-2004-0708 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 18 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | Michael Castleman is credited for this vulnerability. |
| Vulnerable: |
MoinMoin MoinMoin 1.2.1 MoinMoin MoinMoin 1.2 MoinMoin MoinMoin 1.1 |
| Not Vulnerable: |
MoinMoin MoinMoin 1.2.2 |
Discussion
MoinMoin Group Name Privilege Escalation Vulnerability
It is reported that MoinMoin contains a privilege escalation vulnerability whereby regular users can gain administrative privileges.
MoinMoin allows remote web clients to create their own user accounts without administrative intervention or approval. It is reported that if a user creates an account with the same name as an administrative group, the user will inherit the privileges of that same administrative group.
An attacker would use this vulnerability to gain complete access to the MoinMoin Wiki, and could gain access to sensitive information, or destroy information.
Versions before 1.2.2 are reported vulnerable.
It is reported that MoinMoin contains a privilege escalation vulnerability whereby regular users can gain administrative privileges.
MoinMoin allows remote web clients to create their own user accounts without administrative intervention or approval. It is reported that if a user creates an account with the same name as an administrative group, the user will inherit the privileges of that same administrative group.
An attacker would use this vulnerability to gain complete access to the MoinMoin Wiki, and could gain access to sensitive information, or destroy information.
Versions before 1.2.2 are reported vulnerable.
Exploit / POC
MoinMoin Group Name Privilege Escalation Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
MoinMoin Group Name Privilege Escalation Vulnerability
Solution:
Gentoo has released an advisory with updates to address this issue. Updates may be applied with the following commands:
emerge sync
emerge -pv ">=net-ww/moinmoin-1.2.2"
emerge ">=net-ww/moinmoin-1.2.2"
The released version 1.2.2 does not reportedly contain this vulnerability. Users of affected packages are urged to upgrade.
Solution:
Gentoo has released an advisory with updates to address this issue. Updates may be applied with the following commands:
emerge sync
emerge -pv ">=net-ww/moinmoin-1.2.2"
emerge ">=net-ww/moinmoin-1.2.2"
The released version 1.2.2 does not reportedly contain this vulnerability. Users of affected packages are urged to upgrade.