CVE-2011-4581: Infoleak
A number of flaws have been fixed in new upstream Moodle 2.1.3 [1], 2.0.6 [2], and 1.9.15 [3] releases. These do not have CVEs assigned (request pending), and since Fedora/EPEL will rebase to the latest versions of each branch, I'm summarizing them all here rather than creating a number of separate bugs.
[1] http://docs.moodle.org/dev/Moodle2.1.3releasenotes [2] http://docs.moodle.org/dev/Moodle2.0.6releasenotes [3] http://docs.moodle.org/dev/Moodle1.9.15releasenotes
MSA-11-0042: Information leak in Wiki Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=140af2a0f0a4598bf568b9ae182cb81eb583edeb Reference: http://moodle.org/mod/forum/discuss.php?d=191747
MSA-11-0043: Possible link redirect in Calendar Affects: 2.1.x Fix: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-28720&sr=1 Reference: http://moodle.org/mod/forum/discuss.php?d=191748
MSA-11-0044: Expired identification information shown in Web services Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-28670&sr=1 Reference: http://moodle.org/mod/forum/discuss.php?d=191750
MSA-11-0045: Potential to masquerade through MNet Affects: 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=10df8657c1c138c0d0ab1d4796c552fcec0c299b Reference: http://moodle.org/mod/forum/discuss.php?d=191751
MSA-11-0046: Insecure authentication transmission Affects: 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=01dd64a8c8aa95f793accea371b2392e662663c5 Reference: http://moodle.org/mod/forum/discuss.php?d=191752
MSA-11-0047: Possible injection attack in Calendar Affects: 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=581e8dba387f090d89382115fd850d8b44351526 Reference: moodle.org/mod/forum/discuss.php?d=191754
MSA-11-0048: Password loss issue Affects: 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=e079e82c087becf06d902089d14f3f76686bde19 Reference: http://moodle.org/mod/forum/discuss.php?d=191755
MSA-11-0049: Network restriction ineffective with MNet Affects: 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=3ab2851d2a59721445945d0706c58092e07e861e Reference: http://moodle.org/mod/forum/discuss.php?d=191756
MSA-11-0050: Backup capability issue Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-29591 Reference: http://moodle.org/mod/forum/discuss.php?d=191758
MSA-11-0051: Authentication issue with Web services Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-28629 Reference: http://moodle.org/mod/forum/discuss.php?d=191759
MSA-11-0052: Potential to exploit developer debugging scripts Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=187672608ec96659e07f2461b3b83634debd16cb Reference: http://moodle.org/mod/forum/discuss.php?d=191760
MSA-11-0053: Security and system administration conflict Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=ade30ad3c420ce035a3d68287db701b70e806b3f Refrence: http://moodle.org/mod/forum/discuss.php?d=191761
MSA-11-0054: Personal information leak Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=e94113a859015a4a80b9397957b8fc4044e2951f Reference: http://moodle.org/mod/forum/discuss.php?d=191762
Other sources
mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover the username of a wiki creator by visiting the history and deletion user interface.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4581?
The severity of CVE-2011-4581 is not explicitly defined, but it is important to address the flaws that have been fixed in the affected Moodle versions.
Which versions of Moodle are affected by CVE-2011-4581?
CVE-2011-4581 affects Moodle versions 2.0.0 through 2.0.6 and 1.9.15, among others.
How do I fix CVE-2011-4581?
To fix CVE-2011-4581, update your Moodle installation to the latest version available.
Are there known exploits for CVE-2011-4581?
There are no specific exploits reported for CVE-2011-4581, but addressing the vulnerabilities is crucial for maintaining security.
What should I do if I can't update Moodle to fix CVE-2011-4581?
If you cannot update Moodle, consider implementing additional security measures such as firewalls and intrusion detection systems to mitigate risks.