CVE-2021-32472: Infoleak
Published Mar 11, 2022
·Updated
Teachers exporting a forum in CSV format could receive a CSV of forums from all courses in some circumstances. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6 and 3.8 to 3.8.8 are affected.
Affected Software
6 affected componentsFixes available
composer/moodle/moodle>=3.10.0<3.10.4
3.10.4
composer/moodle/moodle>=3.9.0<3.9.7
3.9.7
composer/moodle/moodle>=3.8.0<3.8.9
3.8.9
Moodle moodle>=3.8.0<3.8.9
Moodle moodle>=3.9.0<3.9.7
Moodle moodle>=3.10.0<3.10.4
Remediation
Patch Available
Event History
Mar 11, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Mar 12, 2022
Advisory Published
via GitHub·12:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2021-32472?
CVE-2021-32472 is classified as a medium severity vulnerability.
2
How do I fix CVE-2021-32472?
To fix CVE-2021-32472, upgrade to Moodle version 3.10.4, 3.9.7, or 3.8.9.
3
Who is affected by CVE-2021-32472?
CVE-2021-32472 affects teachers using Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, and 3.8 to 3.8.8.
4
What type of data exposure does CVE-2021-32472 cause?
CVE-2021-32472 can cause unintended exposure of forum data across all courses when exporting to CSV.
5
Is there a workaround for CVE-2021-32472?
There is no confirmed workaround for CVE-2021-32472; updating to the fixed versions is the recommended approach.