{"id":"GHSA-574f-mh6m-c6qm","summary":"MoinMoin has multiple vulnerabilities related to superuser list, xmlrpc and OpenID configuration","details":"Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors, related to configurations that have a non-empty superuser list, the xmlrpc action enabled, the SyncPages action enabled, or OpenID configured.","aliases":["CVE-2010-0668","PYSEC-2010-15"],"modified":"2024-12-06T05:30:42.818286Z","published":"2022-05-02T06:14:39Z","database_specific":{"cwe_ids":[],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-04-29T11:24:59Z","nvd_published_at":"2010-02-26T19:30:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2010-0668"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=565604"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/56002"},{"type":"PACKAGE","url":"https://github.com/moinwiki/moin"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/moin/PYSEC-2010-15.yaml"},{"type":"WEB","url":"https://web.archive.org/web/20111225112846/http://secunia.com/advisories/38903"},{"type":"WEB","url":"https://web.archive.org/web/20140725192956/http://secunia.com/advisories/38709"},{"type":"WEB","url":"https://web.archive.org/web/20140806190238/http://secunia.com/advisories/38444"},{"type":"WEB","url":"https://web.archive.org/web/20200228174758/http://www.securityfocus.com/bid/38023"},{"type":"WEB","url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=569975"},{"type":"WEB","url":"http://hg.moinmo.in/moin/1.8/raw-file/1.8.7/docs/CHANGES"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035374.html"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035438.html"},{"type":"WEB","url":"http://marc.info/?l=oss-security&m=126625972814888&w=2"},{"type":"WEB","url":"http://marc.info/?l=oss-security&m=126676896601156&w=2"},{"type":"WEB","url":"http://moinmo.in/MoinMoinRelease1.8"},{"type":"WEB","url":"http://moinmo.in/SecurityFixes"},{"type":"WEB","url":"http://www.debian.org/security/2010/dsa-2014"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2010/02/15/2"}],"affected":[{"package":{"name":"moin","ecosystem":"PyPI","purl":"pkg:pypi/moin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.5"},{"fixed":"1.8.7"}]}],"versions":["1.8.4","1.8.5","1.8.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-574f-mh6m-c6qm/GHSA-574f-mh6m-c6qm.json"}},{"package":{"name":"moin","ecosystem":"PyPI","purl":"pkg:pypi/moin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.9"},{"fixed":"1.9.2"}]}],"versions":["1.9.0","1.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-574f-mh6m-c6qm/GHSA-574f-mh6m-c6qm.json"}}],"schema_version":"1.9.0"}