id: PYSEC-2020-67 details: The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload attachments to the wiki can use this to achieve remote code execution. affected: - package: name: moin ecosystem: PyPI purl: pkg:pypi/moin ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 1.9.11 versions: - 1.8.4 - 1.8.5 - 1.8.6 - 1.8.7 - 1.9.0 - 1.9.1 - 1.9.2 - 1.9.3 - 1.9.4 - 1.9.5 - 1.9.6 - 1.9.7 - 1.9.8 - 1.9.9 - 1.9.10 references: - type: ADVISORY url: https://www.debian.org/security/2020/dsa-4787 - type: ADVISORY url: https://github.com/moinwiki/moin-1.9/security/advisories/GHSA-52q8-877j-gghq - type: WEB url: http://moinmo.in/SecurityFixes - type: WEB url: https://lists.debian.org/debian-lts-announce/2020/11/msg00020.html aliases: - CVE-2020-25074 - GHSA-52q8-877j-gghq modified: "2020-11-24T17:20:00Z" published: "2020-11-10T17:15:00Z"