GHSA-2m72-m5cw-3g9h
Dashboard / Vulnerabilities / GHSA-2m72-m5cw-3g9h
GHSA-2m72-m5cw-3g9h
Summary: Missing permission check in Moodle
Details: The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-20283, https://bugzilla.redhat.com/show_bug.cgi?id=1939051, https://github.com/moodle/moodle, https://lists.fedoraproject.org/archives/list/[email protected]/message/AFSNJ7XHVTC52RSRX2GBQFF3VEEAY2MS, https://lists.fedoraproject.org/archives/list/[email protected]/message/UFH5DDMU5TZ3JT4Q52WMRAHACA5MHIMT, https://moodle.org/mod/forum/discuss.php?d=419654
Affected packages
Package
Name: moodle/moodle
Purl: pkg:composer/moodle/moodle
Affected ranges
Type: ECOSYSTEM
Events:
