CVE-2017-1000145: Medium severity mahara vulnerability
Published Nov 3, 2017
·Updated
Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to anonymous comments being able to be placed on artefact detail pages even when the site administrator had disallowed anonymous comments.
Affected Software
18 affected components
Mahara Mahara=1.9-rc1
Mahara Mahara=1.9.0
Mahara Mahara=1.9.1
Mahara Mahara=1.9.2
Mahara Mahara=1.9.3
Mahara Mahara=1.9.4
Mahara Mahara=1.9.5
Mahara Mahara=1.9.6
Mahara Mahara=1.10-rc1
Mahara Mahara=1.10.0
Mahara Mahara=1.10.1
Mahara Mahara=1.10.2
Mahara Mahara=1.10.3
Mahara Mahara=1.10.4
Mahara Mahara=15.04-rc1
Mahara Mahara=15.04-rc2
Mahara Mahara=15.04.0
Mahara Mahara=15.04.1
Remediation
Patch Available
Event History
Nov 3, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-1000145?
The severity of CVE-2017-1000145 is medium.
2
What version of Mahara is vulnerable to CVE-2017-1000145?
Mahara versions 1.9 before 1.9.7, 1.10 before 1.10.5, and 15.04 before 15.04.2 are vulnerable to CVE-2017-1000145.
3
What is the impact of CVE-2017-1000145?
CVE-2017-1000145 allows anonymous comments to be placed on artefact detail pages even when the site administrator had disallowed anonymous comments.
4
How can I fix CVE-2017-1000145?
To fix CVE-2017-1000145, upgrade to Mahara versions 1.9.7, 1.10.5, or 15.04.2.
5
Where can I find more information about CVE-2017-1000145?
You can find more information about CVE-2017-1000145 at the following reference: https://bugs.launchpad.net/mahara/+bug/1460368