{"id":"GHSA-cmg7-xr2j-4r9v","summary":"MoinMoin Improper ACL handling for calendars and includes","details":"MoinMoin before 20070507 does not properly enforce ACLs for calendars and includes, which allows remote attackers to read certain pages via unspecified vectors.","aliases":["CVE-2007-2637","PYSEC-2026-675"],"modified":"2026-07-06T08:11:25.484418603Z","published":"2022-05-01T18:05:39Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-05-14T20:41:20Z","nvd_published_at":"2007-05-13T23:19:00Z","cwe_ids":[],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2007-2637"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34474"},{"type":"WEB","url":"https://moinmo.in/MoinMoinRelease1.5/CHANGES"},{"type":"WEB","url":"http://osvdb.org/36269"},{"type":"WEB","url":"http://secunia.com/advisories/25208"},{"type":"WEB","url":"http://secunia.com/advisories/29262"},{"type":"WEB","url":"http://www.debian.org/security/2008/dsa-1514"},{"type":"WEB","url":"http://www.ubuntu.com/usn/usn-458-1"}],"affected":[{"package":{"name":"moin","ecosystem":"PyPI","purl":"pkg:pypi/moin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-cmg7-xr2j-4r9v/GHSA-cmg7-xr2j-4r9v.json"}}],"schema_version":"1.9.0"}