CVE-2020-9386: Infoleak
In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to group members in the Elasticsearch result list despite them not having access to that artefact anymore.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-9386?
CVE-2020-9386 is a vulnerability in Mahara versions 18.10 to 19.10 that allows disclosure of file metadata to group members.
Which versions of Mahara are affected by CVE-2020-9386?
Mahara versions 18.10 to 19.10 are affected by CVE-2020-9386.
What is the severity of CVE-2020-9386?
The severity of CVE-2020-9386 is medium with a CVSS score of 4.3.
How can the file metadata disclosure vulnerability be exploited?
The file metadata disclosure vulnerability can be exploited by disclosing file information to group members in the Elasticsearch result list, even if they no longer have access to the file.
Is there a fix available for CVE-2020-9386?
Yes, upgrades to Mahara version 18.10.5, 19.04.4, or 19.10.2 are available to fix the vulnerability.