CVE-2004-0708: High severity MoinMoin MoinMoin vulnerability
Published Jul 21, 2004
·Updated
MoinMoin 1.2.1 and earlier allows remote attackers to gain privileges by creating a user with the same name as an existing group that has higher privileges.
Affected Software
4 affected componentsFixes available
pip/Moin<=1.2.1
1.2.2
MoinMoin MoinMoin=1.1
MoinMoin MoinMoin=1.2
MoinMoin MoinMoin=1.2.1
Remediation
Patch Available
Patch Available
Event History
Jul 21, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Apr 29, 2022
Advisory Published
via GitHub·02:58 AM
Frequently Asked Questions
1
What is the severity of CVE-2004-0708?
CVE-2004-0708 is considered to have a moderate severity level due to the potential for privilege escalation.
2
How do I fix CVE-2004-0708?
To fix CVE-2004-0708, upgrade to MoinMoin version 1.2.2 or later.
3
What systems are affected by CVE-2004-0708?
CVE-2004-0708 affects MoinMoin versions 1.2.1 and earlier, as well as version 1.1.
4
What vulnerabilities does CVE-2004-0708 exploit?
CVE-2004-0708 exploits a design flaw that allows attackers to create a user with the same name as a higher-privileged group.
5
Is CVE-2004-0708 easy to exploit?
Yes, CVE-2004-0708 can be easily exploited by remote attackers familiar with the MoinMoin user and group structure.