CVE-2020-9387: Infoleak
Published Apr 30, 2020
·Updated
In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' is turned on.
Affected Software
4 affected components
Mahara Mahara>=19.04<19.04.5
Mahara Mahara>=19.10<19.10.3
Mahara Mahara=20.04-rc1
Mahara Mahara=20.04-rc2
Remediation
Patch Available
Event History
Apr 30, 2020
CVE Published
via MITRE·12:46 PM
Data Sourced
via MITRE·12:46 PM
Description
Frequently Asked Questions
1
What is CVE-2020-9387?
CVE-2020-9387 is a vulnerability that exists in Mahara versions 19.04 before 19.04.5 and 19.10 before 19.10.3.
2
How does CVE-2020-9387 affect Mahara?
CVE-2020-9387 allows account details to be shared in the Elasticsearch results for inaccessible accounts when the 'Isolated institutions' config setting is turned on.
3
What is the severity of CVE-2020-9387?
The severity of CVE-2020-9387 is medium with a CVSS score of 4.3.
4
How can I fix CVE-2020-9387?
To fix CVE-2020-9387, upgrade to Mahara versions 19.04.5 or 19.10.3 or later.
5
Where can I find more information about CVE-2020-9387?
More information about CVE-2020-9387 can be found at the following references: [1] [2].