First published: Fri Mar 11 2022(Updated: )
The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affected.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=3.10<3.10.4 | 3.10.4 |
Moodle | >=3.10.0<3.10.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-32477 is rated as a moderate severity vulnerability as it exposes user access timestamps to unauthorized users.
To fix CVE-2021-32477, update Moodle to version 3.10.4 or later.
Moodle versions 3.10 to 3.10.3 are affected by CVE-2021-32477.
By default, only site administrators should be able to see the last access time, but this vulnerability improperly allows broader access.
Yes, CVE-2021-32477 primarily impacts user roles by exposing sensitive access time information to those without the appropriate permissions.