CVE-2024-25982: Msa-24-0005: csrf risk in language import utility
MSA-24-0005: CSRF risk in Language import utility
Description: The link to update all installed language packs did not include the necessary token to prevent a CSRF risk. Issue summary: CSRF risk in Language import utility Severity/Risk: Minor Versions affected: 4.3 to 4.3.2, 4.2 to 4.2.5, 4.1 to 4.1.8 and earlier unsupported versions Versions fixed: 4.3.3, 4.2.6 and 4.1.9 Reported by: Panagiotis Petasis Issue no.: MDL-54749 CVE identifier: Pending Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-54749
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/moodleto a version that resolves this vulnerability.Fixed in 4.3.3 - Upgrade
Upgrade
redhat/4.2.6 andto a version that resolves this vulnerability.Fixed in 4.1.9 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.1.9 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.2.6 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.3.3 - Upgrade
Upgrade
Moodle language import utilityto a version that resolves this vulnerability.Fixed in 4.3.3 - Upgrade
Upgrade
Moodle language import utilityto a version that resolves this vulnerability.Fixed in 4.2.6 - Upgrade
Upgrade
Moodle language import utilityto a version that resolves this vulnerability.Fixed in 4.1.9 - Compensating control
If you cannot upgrade immediately, prevent CSRF exploitation of Moodle Language import utility by ensuring requests that update language packs include the necessary CSRF token (the update link previously lacked the token).
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25982?
The severity of CVE-2024-25982 is classified as minor.
Which versions are affected by CVE-2024-25982?
CVE-2024-25982 affects Moodle versions 4.1.0 to 4.1.9, 4.2.0 to 4.2.6, and 4.3.0 to 4.3.2.
How do I fix CVE-2024-25982?
To fix CVE-2024-25982, update your Moodle installation to version 4.1.10, 4.2.7, or 4.3.3 or later.
Is there a CSRF risk associated with CVE-2024-25982?
Yes, CVE-2024-25982 presents a CSRF risk in the Language import utility due to the absence of a security token.
What should I do if I'm running a vulnerable version for CVE-2024-25982?
If you are running a vulnerable version related to CVE-2024-25982, you should update to the recommended patched versions immediately.