CVE-2012-2357: Infoleak
The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/casform.html in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not use HTTPS, which allows remote attackers to obtain credentials by sniffing the network.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2357?
CVE-2012-2357 is considered a moderate severity vulnerability due to its potential to expose user credentials over unencrypted connections.
How do I fix CVE-2012-2357?
To fix CVE-2012-2357, upgrade Moodle to version 2.1.6 or later for 2.1.x or 2.2.3 or later for 2.2.x.
What are the affected versions for CVE-2012-2357?
CVE-2012-2357 affects Moodle versions 2.1.0 through 2.1.5 and 2.2.0 through 2.2.2.
What does CVE-2012-2357 exploit?
CVE-2012-2357 exploits the lack of HTTPS in the Multi-Authentication feature of the Central Authentication Service in certain Moodle versions.
Is there a workaround for CVE-2012-2357?
A temporary workaround for CVE-2012-2357 is to enable HTTPS on your Moodle instance to secure credentials during transmission.