CVE-2021-36395: High severity moodle vulnerability
Published Mar 6, 2023
·Updated
In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.
Affected Software
3 affected components
Moodle moodle<3.9.8
Moodle moodle>=3.10.0<3.10.5
Moodle moodle>=3.11.0<3.11.1
Remediation
Patch Available
Event History
Mar 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-36395.
2
What is the severity of CVE-2021-36395?
The severity of CVE-2021-36395 is high (7.5).
3
Which software versions are affected by CVE-2021-36395?
Versions up to and including Moodle 3.9.8, Moodle 3.10.0 to 3.10.5, and Moodle 3.11.0 to 3.11.1 are affected by CVE-2021-36395.
4
What is the risk associated with CVE-2021-36395?
CVE-2021-36395 poses a risk of recursion denial of service due to insufficient recursion handling in Moodle's file repository URL parsing.
5
How can I mitigate the risk of CVE-2021-36395?
To mitigate the risk of CVE-2021-36395, it is recommended to update Moodle to a version that includes the necessary recursion handling fix.