First published: Mon Jun 12 2023(Updated: )
An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.
Credit: patrick@puiterwijk.org patrick@puiterwijk.org patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle Moodle | <3.9.22 | |
Moodle Moodle | >=3.11.0<3.11.15 | |
Moodle Moodle | >=4.0.0<4.0.9 | |
Moodle Moodle | >=4.1.0<4.1.4 | |
Moodle Moodle | =4.2.0 | |
composer/moodle/moodle | <3.9.22 | 3.9.22 |
composer/moodle/moodle | >=3.10.0<3.11.15 | 3.11.15 |
composer/moodle/moodle | >=4.0.0<4.0.9 | 4.0.9 |
composer/moodle/moodle | >=4.1.0<4.1.4 | 4.1.4 |
composer/moodle/moodle | =4.2.0 | 4.2.1 |
redhat/moodle | <4.2.1 | 4.2.1 |
redhat/moodle | <4.1.4 | 4.1.4 |
redhat/moodle | <4.0.9 | 4.0.9 |
redhat/moodle | <3.11.15 | 3.11.15 |
redhat/moodle | <3.9.22 | 3.9.22 |
<3.9.22 | ||
>=3.11.0<3.11.15 | ||
>=4.0.0<4.0.9 | ||
>=4.1.0<4.1.4 | ||
=4.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-35133 is high, with a severity value of 7.5.
Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions are affected by CVE-2023-35133.
CVE-2023-35133 poses an SSRF risk.
To mitigate the vulnerability in Moodle, it is recommended to upgrade to the latest supported version or apply the necessary patches provided by Moodle.
Additional information about CVE-2023-35133 can be found in the references section of the vulnerability description.