First published: Thu Nov 14 2019(Updated: )
Moodle before 2.2.2 default settings allowed all repositories to be viewable by all authenticated users.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | <1.9.17 | 1.9.17 |
composer/moodle/moodle | >=2.0<=2.0.7 | 2.0.8 |
composer/moodle/moodle | >=2.1<=2.1.4 | 2.1.5 |
composer/moodle/moodle | >=2.2<=2.2.1 | 2.2.2 |
debian/moodle | ||
Moodle | <2.2.2 | |
Fedora | =15 | |
Fedora | =16 | |
Fedora | =17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1157 is classified as a medium severity vulnerability due to its potential for unauthorized access to sensitive repository data.
To fix CVE-2012-1157, upgrade Moodle to version 2.2.2 or later to ensure proper repository settings.
Moodle versions prior to 2.2.2, including 1.9.17, 2.0.8, and 2.1.5, are affected by CVE-2012-1157.
CVE-2012-1157 is a configuration issue that allows all authenticated users to view all repositories by default.
If you are running Moodle version below 2.2.2, your installation is vulnerable to CVE-2012-1157.