GHSA-mxh8-xgq9-w782

Suggest an improvement
Source
https://github.com/advisories/GHSA-mxh8-xgq9-w782
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mxh8-xgq9-w782/GHSA-mxh8-xgq9-w782.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mxh8-xgq9-w782
Aliases
Published
2022-05-01T17:47:55Z
Modified
2026-07-06T08:11:24.024461879Z
Summary
MoinMoin Insertion of Sensitive Information into Log File
Details

An information leak was discovered in MoinMoin's debug reporting version 1.5.7, which could expose information about the versions of software running on the host system. MoinMoin administrators can add "show_traceback=0" to their site configurations to disable debug tracebacks.

Database specific
{
    "cwe_ids": [
        "CWE-532"
    ],
    "nvd_published_at": "2007-02-13T20:28:00Z",
    "github_reviewed_at": "2024-05-14T20:50:29Z",
    "severity": "MODERATE",
    "github_reviewed": true
}
References

Affected packages

PyPI / moin

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.5.7
Fixed
1.5.8

Affected versions

1.*
1.5.7

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mxh8-xgq9-w782/GHSA-mxh8-xgq9-w782.json"