CVE-2024-38273: moodle: BigBlueButton web service leaks meeting joining information to users who should not have access
Published Jun 18, 2024
·Updated
Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.
Affected Software
10 affected componentsFixes available
composer/moodle/moodle<4.1.11
4.1.11
composer/moodle/moodle>=4.2.0-beta<4.2.8
4.2.8
composer/moodle/moodle>=4.3.0-beta<4.3.5
4.3.5
composer/moodle/moodle>=4.4.0-beta<4.4.1
4.4.1
Moodle Moodle>=4.1.0<4.1.11
Moodle Moodle>=4.2.0<4.2.8
Moodle Moodle>=4.3.0<4.3.5
Moodle Moodle=4.4.0
Fedoraproject Fedora=39
Fedoraproject Fedora=40
Event History
Jun 18, 2024
CVE Published
via MITRE·07:49 PM
Data Sourced
via MITRE·07:49 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
Affected Software
Advisory Published
via GitHub·09:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-38273?
CVE-2024-38273 has been rated as a high severity vulnerability due to insufficient capability checks.
2
How do I fix CVE-2024-38273?
To fix CVE-2024-38273, upgrade your Moodle installation to version 4.1.11, 4.2.8, 4.3.5, or 4.4.1.
3
What are the affected versions for CVE-2024-38273?
CVE-2024-38273 affects Moodle versions prior to 4.1.11, 4.2.8, 4.3.5, and 4.4.1.
4
Can users exploit CVE-2024-38273 remotely?
Yes, users can potentially exploit CVE-2024-38273 remotely to gain unauthorized access to BigBlueButton join URLs.
5
Who is at risk from CVE-2024-38273?
Organizations using affected versions of Moodle may be at risk from CVE-2024-38273 if they haven't applied the necessary updates.