PatchSiren

Ikiwiki CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Ikiwiki CVE published 2017-02-13

CVE-2016-10026

CVE-2016-10026 is a high-severity ikiwiki authorization flaw affecting version 3.20161219 on sites that use the git and recentchanges plugins with the CGI interface enabled. According to the CVE description, the application does not properly check whether a revision changes a page’s access permissions, which can let a remote attacker revert certain changes by taking advantage of permissions that applied b [truncated]