CVE-2021-40695: Infoleak
Published Jan 21, 2022
·Updated
It was possible for a student to view their quiz grade before it had been released, using a quiz web service.
Affected Software
6 affected componentsFixes available
composer/moodle/moodle>=3.9<3.9.10
3.9.10
composer/moodle/moodle>=3.10<3.10.7
3.10.7
composer/moodle/moodle>=3.11<3.11.3
3.11.3
Moodle moodle>=3.9.0<3.9.10
Moodle moodle>=3.10.0<3.10.7
Moodle moodle>=3.11.0<3.11.3
Event History
Jan 21, 2022
Data Sourced
via Red Hat·08:49 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·06:17 PM
Data Sourced
via MITRE·06:17 PM
DescriptionWeakness
Sep 30, 2022
Advisory Published
via GitHub·12:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2021-40695?
CVE-2021-40695 has been classified as a medium severity vulnerability due to its potential impact on student grade privacy.
2
How do I fix CVE-2021-40695?
To fix CVE-2021-40695, upgrade Moodle to version 3.9.10, 3.10.7, or 3.11.3, depending on your current version.
3
Who is affected by CVE-2021-40695?
CVE-2021-40695 affects Moodle installations running versions between 3.9.0 and 3.9.10, 3.10.0 to 3.10.7, and 3.11.0 to 3.11.3.
4
What information can be exposed due to CVE-2021-40695?
CVE-2021-40695 allows students to view their quiz grades before they are officially released, compromising grade confidentiality.
5
Is there a workaround for CVE-2021-40695?
There are no known workarounds for CVE-2021-40695, so upgrading to a fixed version is the only mitigation available.