CVE-2022-0334: Medium severity moodle vulnerability
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view capability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-0334?
CVE-2022-0334 is classified as a medium severity vulnerability due to insufficient capability checks.
How do I fix CVE-2022-0334?
To fix CVE-2022-0334, upgrade Moodle to version 3.11.5 or 3.9.12, or ensure you are running a version beyond the specified vulnerable versions.
What versions of Moodle are affected by CVE-2022-0334?
CVE-2022-0334 affects Moodle versions 3.11.0 to 3.11.4, 3.10.0 to 3.10.8, and 3.9.0 to 3.9.11.
Can CVE-2022-0334 lead to data exposure?
Yes, CVE-2022-0334 can potentially lead to unauthorized users accessing grade reports they are not permitted to view.
Is there a workaround for CVE-2022-0334?
Currently, there is no specific workaround for CVE-2022-0334; the recommended action is to update to a fixed version.