CVE-2022-45152: SSRF
A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems. This vulnerability allows a remote attacker to perform SSRF attacks.
Other sources
MSA-22-0032: Blind SSRF risk in LTI provider library
Moodle's LTI provider library did not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk.
Versions affected: 4.0 to 4.0.4, 3.11 to 3.11.10, 3.9 to 3.9.17 and earlier unsupported versions Versions fixed: 4.0.5, 3.11.11 and 3.9.18
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/moodleto a version that resolves this vulnerability.Fixed in 4.0.5 - Upgrade
Upgrade
redhat/moodleto a version that resolves this vulnerability.Fixed in 3.11.11 - Upgrade
Upgrade
redhat/moodleto a version that resolves this vulnerability.Fixed in 3.9.18 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.0.5 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 3.11.11 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 3.9.18 - Upgrade
Upgrade
Moodleto a version that resolves this vulnerability.Fixed in 4.0.5Patch MSA-22-0032 - Upgrade
Upgrade
Moodleto a version that resolves this vulnerability.Fixed in 3.11.11Patch MSA-22-0032 - Upgrade
Upgrade
Moodleto a version that resolves this vulnerability.Fixed in 3.9.18Patch MSA-22-0032
Event History
Frequently Asked Questions
What is CVE-2022-45152?
CVE-2022-45152 is a blind Server-Side Request Forgery (SSRF) vulnerability found in Moodle.
How does CVE-2022-45152 occur?
CVE-2022-45152 occurs due to insufficient validation of user-supplied input in Moodle's LTI provider library.
What is the severity of CVE-2022-45152?
CVE-2022-45152 has a severity of 9.1 out of 10, which is critical.
Which versions of Moodle are affected by CVE-2022-45152?
Versions up to Moodle 3.9.18, Moodle 3.11.0 to 3.11.11, and Moodle 4.0.0 to 4.0.5 are affected by CVE-2022-45152.
How can CVE-2022-45152 be fixed?
To fix CVE-2022-45152, users should update to Moodle version 3.9.18, 3.11.11, or 4.0.5.