First published: Tue Aug 16 2022(Updated: )
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of service.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle Moodle | >=3.5.0<3.5.13 | |
Moodle Moodle | >=3.7.0<3.7.7 | |
Moodle Moodle | >=3.8.0<3.8.4 | |
Moodle Moodle | =3.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-14322 is high with a CVSS score of 7.5.
Moodle versions 3.5.0 to 3.5.13, 3.7.0 to 3.7.7, 3.8.0 to 3.8.4, and 3.9.0 are affected by CVE-2020-14322.
CVE-2020-14322 poses a risk of denial of service.
To mitigate the risk of CVE-2020-14322, ensure that yui_combo limits the number of files it can load.
You can find more information about CVE-2020-14322 at the following link: [Moodle Forum](https://moodle.org/mod/forum/discuss.php?d=407394)