CVE-2021-40691: Medium severity moodle vulnerability
Published Jan 21, 2022
·Updated
A session hijack risk was identified in the Shibboleth authentication plugin.
Affected Software
6 affected componentsFixes available
composer/moodle/moodle>=3.11<3.11.3
3.11.3
composer/moodle/moodle>=3.10<3.10.7
3.10.7
composer/moodle/moodle>=3.9<3.9.10
3.9.10
Moodle moodle<3.9.10
Moodle moodle>=3.10.0<3.10.7
Moodle moodle>=3.11.0<3.11.3
Event History
Jan 21, 2022
Data Sourced
via Red Hat·08:33 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·06:17 PM
Data Sourced
via MITRE·06:17 PM
DescriptionWeakness
Sep 30, 2022
Advisory Published
via GitHub·12:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2021-40691?
CVE-2021-40691 is considered a critical vulnerability due to its potential for session hijacking.
2
How do I fix CVE-2021-40691?
To mitigate CVE-2021-40691, upgrade to Moodle version 3.11.3, 3.10.7, or 3.9.10.
3
What systems are affected by CVE-2021-40691?
CVE-2021-40691 affects Moodle versions from 3.9.0 up to 3.11.2 and earlier.
4
What impact does CVE-2021-40691 have on users?
CVE-2021-40691 allows attackers to hijack active user sessions, compromising user accounts and data.
5
Is there a workaround for CVE-2021-40691 if I can't upgrade?
There is no known workaround for CVE-2021-40691, and upgrading to the latest version is strongly recommended.