CVE-2008-0169: Medium severity ikiwiki hosting project vulnerability
Plugin/passwordauth.pm (aka the passwordauth plugin) in ikiwiki 1.34 through 2.47 allows remote attackers to bypass authentication, and login to any account for which an OpenID identity is configured and a password is not configured, by specifying an empty password during the login sequence.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0169?
CVE-2008-0169 has a medium severity level as it allows remote attackers to bypass authentication.
How do I fix CVE-2008-0169?
To fix CVE-2008-0169, update ikiwiki to version 2.48 or later where this vulnerability is patched.
What versions of ikiwiki are affected by CVE-2008-0169?
CVE-2008-0169 affects versions of ikiwiki from 1.34 to 2.47.
What does CVE-2008-0169 exploit?
CVE-2008-0169 exploits a flaw in the passwordauth plugin that allows login without a password for certain OpenID accounts.
Who can be targeted by CVE-2008-0169?
CVE-2008-0169 can target any user account configured with an OpenID identity without a password.