Webmin 0.84 and earlier does not properly clear the HTTP_AUTHORIZATION environment variable when the web server is restarted, which makes authentication information available to all CGI programs and allows local users to gain privileges.
| Software | From | Fixed in |
|---|---|---|
| webmin / webmin | 0.7 | 0.7.x |
| webmin / webmin | 0.6 | 0.6.x |
| webmin / webmin | 0.83 | 0.83.x |
| webmin / webmin | 0.84 | 0.84.x |
| webmin / webmin | 0.80 | 0.80.x |
| webmin / webmin | 0.5 | 0.5.x |