CVE-2022-30598: Infoleak
A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access to it.
Other sources
Global search results could include author information on some activities where a user may not otherwise have access to it.
Versions affected: 4.0, 3.11 to 3.11.6, 3.10 to 3.10.10, 3.9 to 3.9.13 and earlier unsupported versions Versions fixed : 4.0.1, 3.11.7, 3.10.11 and 3.9.14
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-30598?
CVE-2022-30598 is a vulnerability in Moodle that allows global search results to include author information on some activities where a user may not have access to it.
How severe is CVE-2022-30598?
CVE-2022-30598 has a severity rating of 4.3, which is considered medium.
Which versions of Moodle are affected by CVE-2022-30598?
Moodle versions 3.9 to 3.9.14, 3.10 to 3.10.11, 3.11 to 3.11.7, and 4.0 to 4.0.1 are affected by CVE-2022-30598.
How can I fix CVE-2022-30598?
To fix CVE-2022-30598, upgrade your Moodle installation to version 3.9.14, 3.10.11, 3.11.7, or 4.0.1, depending on the version you are using.
Where can I find more information about CVE-2022-30598?
You can find more information about CVE-2022-30598 at the following references: - [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-30598) - [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2083592) - [Moodle Forum](https://moodle.org/mod/forum/discuss.php?d=434580)