CVE-2020-14322: High severity moodle vulnerability
Published Aug 16, 2022
·Updated
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yuicombo needed to limit the amount of files it can load to help mitigate the risk of denial of service.
Affected Software
4 affected components
Moodle moodle>=3.5.0<3.5.13
Moodle moodle>=3.7.0<3.7.7
Moodle moodle>=3.8.0<3.8.4
Moodle moodle=3.9.0
Remediation
Patch Available
Event History
Aug 16, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-14322?
The severity of CVE-2020-14322 is high with a CVSS score of 7.5.
2
Which versions of Moodle are affected by CVE-2020-14322?
Moodle versions 3.5.0 to 3.5.13, 3.7.0 to 3.7.7, 3.8.0 to 3.8.4, and 3.9.0 are affected by CVE-2020-14322.
3
What is the risk associated with CVE-2020-14322?
CVE-2020-14322 poses a risk of denial of service.
4
How can I mitigate the risk of CVE-2020-14322?
To mitigate the risk of CVE-2020-14322, ensure that yui_combo limits the number of files it can load.
5
Where can I find more information about CVE-2020-14322?
You can find more information about CVE-2020-14322 at the following link: [Moodle Forum](https://moodle.org/mod/forum/discuss.php?d=407394)