CVE-2022-40314: Code Injection
A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.
Other sources
Severity/Risk: Serious Versions affected: 4.0 to 4.0.3, 3.11 to 3.11.9, 3.9 to 3.9.16 and earlier unsupported versions Versions fixed: 4.0.4, 3.11.10 and 3.9.17 Reported by: Paul Holden CVE identifier: CVE-2022-40314 Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-75405 Tracker issue: MDL-75405 Remote code execution risk when restoring malformed backup file from Moodle 1.9
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.0.4 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 3.11.10 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 3.9.17 - Upgrade
Upgrade
Moodleto a version that resolves this vulnerability.Fixed in 4.0.4 - Upgrade
Upgrade
Moodleto a version that resolves this vulnerability.Fixed in 3.11.10 - Upgrade
Upgrade
Moodleto a version that resolves this vulnerability.Fixed in 3.9.17
Event History
Frequently Asked Questions
What is CVE-2022-40314?
CVE-2022-40314 is a vulnerability that allows remote code execution when restoring backup files originating from Moodle 1.9.
What software is affected by CVE-2022-40314?
The affected software includes Moodle versions between 3.9.0 and 3.9.17, between 3.11.0 and 3.11.10, and between 4.0.0 and 4.0.4.
How severe is CVE-2022-40314?
CVE-2022-40314 is classified as critical with a severity rating of 9.8.
How can I fix CVE-2022-40314?
To fix CVE-2022-40314, it is recommended to upgrade Moodle to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2022-40314?
More information about CVE-2022-40314 can be found at the following references: [Red Hat Security Advisory](https://access.redhat.com/security/cve/CVE-2022-40314), [Moodle Git Repository](http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-75405), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2128147)