CVE-2008-1937: High severity mastodon vulnerability
Published Apr 24, 2008
·Updated
The user form processing (userform.py) in MoinMoin before 1.6.3, when using ACLs or a non-empty superusers list, does not properly manage users, which allows remote attackers to gain privileges.
Affected Software
4 affected componentsFixes available
pip/moin<1.6.3
1.6.3
MoinMoin MoinMoin=1.6.0
MoinMoin MoinMoin=1.6.1
MoinMoin MoinMoin=1.6.2
Remediation
Patch Available
Event History
Apr 24, 2008
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
May 1, 2022
Advisory Published
via GitHub·11:45 PM
Frequently Asked Questions
1
What is the severity of CVE-2008-1937?
CVE-2008-1937 is considered a high severity vulnerability due to its ability to allow remote attackers to gain unauthorized privileges.
2
How do I fix CVE-2008-1937?
To fix CVE-2008-1937, upgrade MoinMoin to version 1.6.3 or later.
3
Which versions of MoinMoin are affected by CVE-2008-1937?
CVE-2008-1937 affects MoinMoin versions 1.6.0, 1.6.1, and 1.6.2.
4
What component is vulnerable in CVE-2008-1937?
The vulnerability in CVE-2008-1937 is found in the user form processing module, userform.py.
5
What types of attacks are possible with CVE-2008-1937?
CVE-2008-1937 enables remote attackers to exploit user management flaws, resulting in privilege escalation.