Lucene search

K
githubGitHub Advisory DatabaseGHSA-574F-MH6M-C6QM
HistoryMay 02, 2022 - 6:14 a.m.

MoinMoin has multiple vulnerabilities related to superuser list, xmlrpc and OpenID configuration

2022-05-0206:14:39
GitHub Advisory Database
github.com
11
moinmoin
vulnerabilities
superuser list
xmlrpc
openid
configuration

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.6

Confidence

Low

EPSS

0.012

Percentile

85.2%

Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors, related to configurations that have a non-empty superuser list, the xmlrpc action enabled, the SyncPages action enabled, or OpenID configured.

Affected configurations

Vulners
Node
moinRange1.91.9.2
OR
moinRange1.51.8.7
VendorProductVersionCPE
*moin*cpe:2.3:a:*:moin:*:*:*:*:*:*:*:*

References

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.6

Confidence

Low

EPSS

0.012

Percentile

85.2%