[ moin-Bugs-948103 ] SECURITY: possible way to defeat ACLs
"SourceForge.net" <[email protected]>
| Newsgroups | gmane.comp.web.wiki.moin.devel |
|---|---|
| Message-ID | <[email protected]> |
Bugs item #948103, was opened at 2004-05-04 20:25 Message generated for change (Tracker Item Submitted) made by Item Submitter You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=108482&aid=948103&group_id=8482 Category: None Group: None Status: Open Resolution: None Priority: 5 Submitted By: Michael Castleman (mlc) Assigned to: Nobody/Anonymous (nobody) Summary: SECURITY: possible way to defeat ACLs Initial Comment: Suppose that you have a group called AdminGroup with special privileges. An attacker can then create a *user* called AdminGroup and gain those privileges. The work around is for the site admin to create an account called AdminGroup and forget the password, but a better solution would be for MoinMoin to forbid creation of accounts which mach the page_group_regex. I can read Python but not write it, otherwise I'd fix this bug myself. Shouldn't be too hard, though. ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=108482&aid=948103&group_id=8482 ------------------------------------------------------- This SF.Net email is sponsored by: Oracle 10g Get certified on the hottest thing ever to hit the market... Oracle 10g. Take an Oracle 10g class now, and we'll give you the exam FREE. http://ads.osdn.com/?ad_id=3149&alloc_id=8166&op=click