CVE-2021-20281: Infoleak
It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
Other sources
It was possible for some users without permission to view other users' full names to do so via the online users block.
References:
https://moodle.org/mod/forum/discuss.php?d=419652
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20281?
CVE-2021-20281 is rated as a medium severity vulnerability.
How do I fix CVE-2021-20281?
To fix CVE-2021-20281, update your Moodle installation to version 3.10.2, 3.9.5, 3.8.8, or 3.5.17 or higher.
Who is affected by CVE-2021-20281?
Users running Moodle versions prior to 3.10.2, 3.9.5, 3.8.8, and 3.5.17 are affected by CVE-2021-20281.
What type of vulnerability is CVE-2021-20281?
CVE-2021-20281 is an information disclosure vulnerability.
What should I do if I can't update to the patched version for CVE-2021-20281?
If you cannot update to the patched versions, review your user permissions to limit access to sensitive user information.