First published: Tue Sep 20 2022(Updated: )
Severity/Risk: Minor Versions affected: 4.0 to 4.0.3, 3.11 to 3.11.9, 3.9 to 3.9.16 and earlier unsupported versions Versions fixed: 4.0.4, 3.11.10 and 3.9.17 Reported by: Jari Vilkman and Bjørn Teistung Workaround: Access to this feature can be revoked by removing the mod/h5pactivity:reviewattempts capability from relevant users until the patch is applied. CVE identifier: <a href="https://access.redhat.com/security/cve/CVE-2022-40316">CVE-2022-40316</a> Changes (master): <a href="http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-71662">http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-71662</a> <a href="http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-72012">http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-72012</a> Tracker issue: MDL-71662 and MDL-72012 No groups filtering in H5P activity attempts report
Credit: patrick@puiterwijk.org patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle Moodle | >=3.9.0<3.9.17 | |
Moodle Moodle | >=3.11.0<3.11.10 | |
Moodle Moodle | >=4.0.0<4.0.4 | |
Fedoraproject Extra Packages For Enterprise Linux | =8.0 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
composer/moodle/moodle | >=4.0<4.0.4 | 4.0.4 |
composer/moodle/moodle | >=3.11<3.11.10 | 3.11.10 |
composer/moodle/moodle | >=3.9<3.9.17 | 3.9.17 |
>=3.9.0<3.9.17 | ||
>=3.11.0<3.11.10 | ||
>=4.0.0<4.0.4 | ||
=8.0 | ||
=35 | ||
=36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40316 is a vulnerability in the H5P activity attempts report in Moodle, which allows non-editing teachers to access information about attempts/users in groups they should not have access to.
CVE-2022-40316 has a severity rating of 4.3 (medium).
CVE-2022-40316 affects Moodle versions 3.9.0 to 3.9.17, 3.11.0 to 3.11.10, and 4.0.0 to 4.0.4.
Non-editing teachers can exploit CVE-2022-40316 by accessing the H5P activity attempts report in Moodle, bypassing group restrictions and gaining unauthorized access to information.
To fix CVE-2022-40316, update your Moodle installation to a version that includes the necessary security patches.