CVE-2009-4405: Trac is vulnerable to improper policy checks and missing 'raw' role check in docutils
(updated )
Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, possibly related to (1) “policy checks in report results when using alternate formats” or (2) a “check for the ‘raw’ role that is missing in docutils < 0.6.”
References
- bugzilla.redhat.com/show_bug.cgi?id=542394
- exchange.xforce.ibmcloud.com/vulnerabilities/54983
- github.com/advisories/GHSA-f9qv-j5g6-g5cr
- github.com/pypa/advisory-database/tree/main/vulns/trac/PYSEC-2009-7.yaml
- nvd.nist.gov/vuln/detail/CVE-2009-4405
- web.archive.org/web/20130417170303/http://secunia.com/advisories/37901
- web.archive.org/web/20130513235205/http://secunia.com/advisories/37807
- www.redhat.com/archives/fedora-package-announce/2009-December/msg01169.html
Detect and mitigate CVE-2009-4405 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →