CVE-2021-40693: Medium severity moodle vulnerability
Published Jan 21, 2022
·Updated
An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.
Affected Software
6 affected componentsFixes available
composer/moodle/moodle>=3.11<3.11.3
3.11.3
composer/moodle/moodle>=3.10<3.10.7
3.10.7
composer/moodle/moodle>=3.9<3.9.10
3.9.10
Moodle moodle<3.9.10
Moodle moodle>=3.10.0<3.10.7
Moodle moodle>=3.11.0<3.11.3
Event History
Jan 21, 2022
Data Sourced
via Red Hat·08:43 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·06:17 PM
Data Sourced
via MITRE·06:17 PM
DescriptionWeakness
Sep 30, 2022
Advisory Published
via GitHub·12:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2021-40693?
CVE-2021-40693 has a severity rating that poses a significant risk of authentication bypass.
2
How do I fix CVE-2021-40693?
To fix CVE-2021-40693, upgrade to Moodle versions 3.11.3, 3.10.7, or 3.9.10.
3
Which Moodle versions are affected by CVE-2021-40693?
CVE-2021-40693 affects Moodle versions before 3.9.10, between 3.10.0 and 3.10.7, and between 3.11.0 and 3.11.3.
4
What type of vulnerability is CVE-2021-40693?
CVE-2021-40693 is classified as a type juggling vulnerability resulting in an authentication bypass.
5
Can CVE-2021-40693 affect external database authentication?
Yes, CVE-2021-40693 specifically impacts the external database authentication functionality in Moodle.