First published: Mon Mar 15 2021(Updated: )
The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle Moodle | >=3.5.0<3.5.17 | |
Moodle Moodle | >=3.8.0<3.8.8 | |
Moodle Moodle | >=3.9.0<3.9.5 | |
Moodle Moodle | >=3.10.0<3.10.2 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =34 | |
composer/moodle/moodle | <3.5.17 | 3.5.17 |
composer/moodle/moodle | >=3.8.0<3.8.8 | 3.8.8 |
composer/moodle/moodle | >=3.9.0<3.9.5 | 3.9.5 |
composer/moodle/moodle | >=3.10.0<3.10.2 | 3.10.2 |
redhat/moodle | <3.10.2 | 3.10.2 |
redhat/moodle | <3.9.5 | 3.9.5 |
redhat/moodle | <3.8.8 | 3.8.8 |
redhat/moodle | <3.5.17 | 3.5.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.