CVE-2021-32477: Infoleak
Published Mar 11, 2022
·Updated
The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affected.
Affected Software
2 affected componentsFixes available
composer/moodle/moodle>=3.10<3.10.4
3.10.4
Moodle moodle>=3.10.0<3.10.4
Remediation
Patch Available
Event History
Mar 11, 2022
CVE Published
via MITRE·05:54 PM
Data Sourced
via MITRE·05:54 PM
DescriptionWeakness
Mar 12, 2022
Advisory Published
via GitHub·12:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2021-32477?
CVE-2021-32477 is rated as a moderate severity vulnerability as it exposes user access timestamps to unauthorized users.
2
How do I fix CVE-2021-32477?
To fix CVE-2021-32477, update Moodle to version 3.10.4 or later.
3
What versions of Moodle are affected by CVE-2021-32477?
Moodle versions 3.10 to 3.10.3 are affected by CVE-2021-32477.
4
Who can access the last time a user accessed the mobile app as per CVE-2021-32477?
By default, only site administrators should be able to see the last access time, but this vulnerability improperly allows broader access.
5
Is CVE-2021-32477 specific to any particular user role in Moodle?
Yes, CVE-2021-32477 primarily impacts user roles by exposing sensitive access time information to those without the appropriate permissions.