CVE-2022-30600: Critical severity Moodle Moodle vulnerability
A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.
Other sources
An issue in the logic used to count failed login attempts could result in the account lockout threshold being bypassed.
Versions affected: 4.0, 3.11 to 3.11.6, 3.10 to 3.10.10, 3.9 to 3.9.13 and earlier unsupported versions Versions fixed : 4.0.1, 3.11.7, 3.10.11 and 3.9.14
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-30600?
CVE-2022-30600 has a severity rating that could potentially allow unauthorized access if exploited.
How do I fix CVE-2022-30600?
To fix CVE-2022-30600, upgrade Moodle to version 3.11.7, 3.10.11, 3.9.14, or 4.0.1 or later.
Which versions of Moodle are affected by CVE-2022-30600?
Versions affected by CVE-2022-30600 include Moodle 4.0, 3.11 to 3.11.6, and earlier versions.
What impact does CVE-2022-30600 have on user accounts?
CVE-2022-30600 may allow attackers to bypass the account lockout threshold, potentially leading to unauthorized access.
Is CVE-2022-30600 a threat to all Moodle installations?
CVE-2022-30600 poses a threat specifically to Moodle installations that are running the affected versions.