First published: Thu Aug 25 2022(Updated: )
============================================================================== MSA-22-0022: CSRF risk in enabling/disabling installed H5P libraries Description: Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk. Issue summary: CSRF risk in enabling/disabling installed H5P libraries Severity/Risk: Minor Versions affected: 4.0 to 4.0.2 and 3.11 to 3.11.8 Versions fixed: 4.0.3 and 3.11.9 Reported by: Paul Holden Issue no.: MDL-75326 CVE identifier: Pending Changes (master): <a href="http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-75326">http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-75326</a> ==============================================================================
Credit: patrick@puiterwijk.org patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle Moodle | >=3.11.0<3.11.9 | |
Moodle Moodle | >=4.0.0<4.0.3 | |
redhat/moodle 4.0.3 and moodle | <3.11.9 | 3.11.9 |
composer/moodle/moodle | >=4.0<4.0.3 | 4.0.3 |
composer/moodle/moodle | >=3.11<3.11.9 | 3.11.9 |
>=3.11.0<3.11.9 | ||
>=4.0.0<4.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2986 is a vulnerability that allows attackers to perform Cross-Site Request Forgery (CSRF) attacks by enabling or disabling installed H5P libraries without the necessary token.
Moodle versions between 3.11.0 and 3.11.9, and Moodle versions between 4.0.0 and 4.0.3 are affected by CVE-2022-2986.
CVE-2022-2986 has a severity value of 8.8, which is considered high.
To fix CVE-2022-2986, upgrade your Moodle installation to version 3.11.9 or higher for versions 3.11.x, and version 4.0.3 or higher for versions 4.0.x.
You can find more information about CVE-2022-2986 in the following references: [Git commit](http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-75326), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2121360), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2122182).