BIT-moodle-2021-20283
Dashboard / Vulnerabilities / BIT-moodle-2021-20283
BIT-moodle-2021-20283
Summary:
Details: The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
References: https://bugzilla.redhat.com/show_bug.cgi?id=1939051, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AFSNJ7XHVTC52RSRX2GBQFF3VEEAY2MS/, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UFH5DDMU5TZ3JT4Q52WMRAHACA5MHIMT/, https://moodle.org/mod/forum/discuss.php?d=419654, https://nvd.nist.gov/vuln/detail/CVE-2021-20283
Affected packages
Package
Name: moodle
Purl: pkg:bitnami/moodle
Affected ranges
Type: SEMVER
Events:
