CVE-2008-6548: Medium severity MoinMoin vulnerability
Published Mar 30, 2009
·Updated
The rst parser (parser/textrst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorized include files via unknown vectors.
Affected Software
2 affected componentsFixes available
pip/moin<1.6.2
1.6.2
MoinMoin=1.6.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/mointo a version that resolves this vulnerability.Fixed in 1.6.2
Event History
Mar 30, 2009
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·01:30 AM
DescriptionSeverityWeaknessAffected Software
May 17, 2022
Advisory Published
via GitHub·05:52 AM
Frequently Asked Questions
1
What is the severity of CVE-2008-6548?
CVE-2008-6548 is a medium severity vulnerability that allows unauthorized reading of files due to ACL checks not being enforced.
2
How do I fix CVE-2008-6548?
To fix CVE-2008-6548, upgrade to MoinMoin version 1.6.2 or later.
3
What systems are affected by CVE-2008-6548?
CVE-2008-6548 affects MoinMoin version 1.6.1 and earlier versions.
4
What type of vulnerability is CVE-2008-6548?
CVE-2008-6548 is an access control vulnerability related to the rst parser in MoinMoin.
5
Can CVE-2008-6548 lead to sensitive data exposure?
Yes, CVE-2008-6548 can lead to unauthorized access to sensitive data through included pages.