« Volver al listado

CVE-2010-0667

Estado: ModificadaMedia (5)—

MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-0667",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-02-26T19:30:00.463",
  "references": [
    {
      "url": "http://hg.moinmo.in/moin/1.9/raw-file/1.9.1/docs/CHANGES",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://hg.moinmo.in/moin/1.9/rev/04afdde50094",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://hg.moinmo.in/moin/1.9/rev/9d8e7ce3c3a2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=oss-security&m=126625972814888&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=oss-security&m=126676896601156&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://moinmo.in/MoinMoinChat/Logs/moin-dev/2010-01-18",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://moinmo.in/SecurityFixes",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/38242",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2010/01/21/6",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2010/02/15/2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://hg.moinmo.in/moin/1.9/raw-file/1.9.1/docs/CHANGES",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://hg.moinmo.in/moin/1.9/rev/04afdde50094",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://hg.moinmo.in/moin/1.9/rev/9d8e7ce3c3a2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marc.info/?l=oss-security&m=126625972814888&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marc.info/?l=oss-security&m=126676896601156&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://moinmo.in/MoinMoinChat/Logs/moin-dev/2010-01-18",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://moinmo.in/SecurityFixes",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/38242",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2010/01/21/6",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2010/02/15/2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "MoinMoin v1.9 anteriores v1.9.1 no realiza de la forma esperada la limpieza del array sys.argv en situaciones donde la variable de entorno  GATEWAY_INTERFACE recibe valor, lo que permite a atacantes remotos conseguir información sensible a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-16T23:16:37.003",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:moinmo:moinmoin:1.9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BAA73028-4193-49E9-B017-F1F27075FDDE"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}