CVE-2016-9645: Editing restriction bypass for git revert
Published Apr 10, 2018
·Updated
The fix for ikiwiki for CVE-2016-10026 was incomplete resulting in editing restriction bypass for git revert when using git versions older than 2.8.0. This has been fixed in 3.20161229.
Affected Software
2 affected componentsFixes available
Ikiwiki ikiwiki<2.8
debian/ikiwiki
3.20200202.3-13.20250501-13.20260201-3
Event History
Apr 10, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Feb 19, 2026
Data Sourced
via Debian·07:12 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9645?
The severity of CVE-2016-9645 is classified as moderate.
2
How do I fix CVE-2016-9645?
To fix CVE-2016-9645, upgrade to Ikiwiki version 3.20161229 or later.
3
What was the cause of CVE-2016-9645?
CVE-2016-9645 was caused by an incomplete fix for CVE-2016-10026, allowing editing restriction bypass.
4
Which versions of Ikiwiki are affected by CVE-2016-9645?
Ikiwiki versions prior to 3.20161229, specifically those before version 2.8, are affected by CVE-2016-9645.
5
Can Git versions older than 2.8.0 exploit CVE-2016-9645?
Yes, Git versions older than 2.8.0 can exploit the vulnerability outlined in CVE-2016-9645.