Candidate: CVE-2017-0356 PublicDate: 2018-04-13 15:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0356 https://ikiwiki.info/security/#cve-2017-0356 Description: A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_ikiwiki: upstream_ikiwiki: released (3.20170111) precise_ikiwiki: ignored (reached end-of-life) precise/esm_ikiwiki: DNE (precise was needed) trusty_ikiwiki: ignored (reached end-of-life) trusty/esm_ikiwiki: DNE (trusty was needed) vivid/stable-phone-overlay_ikiwiki: DNE vivid/ubuntu-core_ikiwiki: DNE xenial_ikiwiki: ignored (end of standard support, was needed) yakkety_ikiwiki: ignored (reached end-of-life) zesty_ikiwiki: ignored (reached end-of-life) artful_ikiwiki: ignored (reached end-of-life) bionic_ikiwiki: not-affected (3.20180228-1) cosmic_ikiwiki: not-affected (3.20180228-1) disco_ikiwiki: not-affected (3.20180228-1) eoan_ikiwiki: not-affected (3.20180228-1) focal_ikiwiki: not-affected (3.20180228-1) groovy_ikiwiki: not-affected (3.20180228-1) hirsute_ikiwiki: not-affected (3.20180228-1) impish_ikiwiki: not-affected (3.20180228-1) jammy_ikiwiki: not-affected (3.20180228-1) devel_ikiwiki: not-affected (3.20180228-1)