id: PYSEC-2010-13 details: MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchical ACLs, which allows remote attackers to bypass intended access restrictions by requesting an item, a different vulnerability than CVE-2008-6603. affected: - package: name: moin ecosystem: PyPI purl: pkg:pypi/moin ranges: - type: ECOSYSTEM events: - introduced: "1.7" - fixed: 1.7.3 - introduced: "1.8" - fixed: 1.8.3 references: - type: ADVISORY url: http://www.vupen.com/english/advisories/2010/0600 - type: WEB url: http://moinmo.in/SecurityFixes - type: ADVISORY url: http://www.debian.org/security/2010/dsa-2014 - type: WEB url: http://hg.moinmo.in/moin/1.8/rev/897cdbe9e8f2 - type: WEB url: http://hg.moinmo.in/moin/1.7/rev/897cdbe9e8f2 - type: WEB url: http://www.securityfocus.com/bid/35277 - type: ADVISORY url: http://secunia.com/advisories/39887 - type: ADVISORY url: http://www.vupen.com/english/advisories/2010/1208 - type: WEB url: http://ubuntu.com/usn/usn-941-1 - type: ADVISORY url: https://github.com/advisories/GHSA-jj23-fj2v-m872 aliases: - CVE-2009-4762 - GHSA-jj23-fj2v-m872 modified: "2010-05-27T05:47:00Z" published: "2010-03-29T20:30:00Z"