MoinMoin Exposure of Sensitive Disclosure when GATEWAY_INTERFACE variable is set
High severity
GitHub Reviewed
Published
May 2, 2022
to the GitHub Advisory Database
•
Updated Sep 30, 2024
Description
Published by the National Vulnerability Database
Feb 26, 2010
Published to the GitHub Advisory Database
May 2, 2022
Reviewed
Apr 1, 2024
Last updated
Sep 30, 2024
MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the
GATEWAY_INTERFACE
environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vectors.References