CVE-2023-35133: Moodle: ssrf risk due to insufficient check on the curl blocked hosts
An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/moodleto a version that resolves this vulnerability.Fixed in 4.2.1 - Upgrade
Upgrade
redhat/moodleto a version that resolves this vulnerability.Fixed in 4.1.4 - Upgrade
Upgrade
redhat/moodleto a version that resolves this vulnerability.Fixed in 4.0.9 - Upgrade
Upgrade
redhat/moodleto a version that resolves this vulnerability.Fixed in 3.11.15 - Upgrade
Upgrade
redhat/moodleto a version that resolves this vulnerability.Fixed in 3.9.22 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 3.9.22 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 3.11.15 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.0.9 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.1.4 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.2.1 - Upgrade
Upgrade
Moodleto a version that resolves this vulnerability.Fixed in 4.2
Event History
Frequently Asked Questions
What is the severity of CVE-2023-35133?
The severity of CVE-2023-35133 is high, with a severity value of 7.5.
Which versions of Moodle are affected by CVE-2023-35133?
Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions are affected by CVE-2023-35133.
What is the risk associated with CVE-2023-35133?
CVE-2023-35133 poses an SSRF risk.
How can I mitigate the vulnerability in Moodle?
To mitigate the vulnerability in Moodle, it is recommended to upgrade to the latest supported version or apply the necessary patches provided by Moodle.
Where can I find more information about CVE-2023-35133?
Additional information about CVE-2023-35133 can be found in the references section of the vulnerability description.