CVE-2017-1000157: Infoleak
Mahara 15.04 before 15.04.13 and 16.04 before 16.04.7 and 16.10 before 16.10.4 and 17.04 before 17.04.2 are vulnerable to recording plain text passwords in the eventlog table during the user creation process if full event logging was turned on.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-1000157 vulnerability?
CVE-2017-1000157 is a vulnerability in Mahara versions 15.04 to 17.04.2 that allows plain text passwords to be recorded in the event_log table during the user creation process.
How severe is CVE-2017-1000157 vulnerability?
CVE-2017-1000157 has a severity rating of 4.4 out of 10.
What is the affected software for CVE-2017-1000157 vulnerability?
The affected software for CVE-2017-1000157 vulnerability is Mahara versions 15.04 to 17.04.2.
How can I fix CVE-2017-1000157 vulnerability?
To fix CVE-2017-1000157 vulnerability, upgrade to Mahara versions 15.04.13, 16.04.7, 16.10.4, or 17.04.2.
Where can I find more information about CVE-2017-1000157 vulnerability?
You can find more information about CVE-2017-1000157 vulnerability at the following link: [CVE-2017-1000157](https://bugs.launchpad.net/mahara/+bug/1692749).