CVE-2024-38277: moodle: QR login key and auto-login key for the Moodle mobile app should be generated as separate keys
Published Jun 18, 2024
·Updated
A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.
Affected Software
10 affected componentsFixes available
composer/moodle/moodle<4.1.11
4.1.11
composer/moodle/moodle>=4.2.0-beta<4.2.8
4.2.8
composer/moodle/moodle>=4.3.0-beta<4.3.5
4.3.5
composer/moodle/moodle>=4.4.0-beta<4.4.1
4.4.1
Moodle Moodle>=4.1.0<4.1.11
Moodle Moodle>=4.2.0<4.2.8
Moodle Moodle>=4.3.0<4.3.5
Moodle Moodle=4.4.0
Fedoraproject Fedora=39
Fedoraproject Fedora=40
Event History
Jun 18, 2024
CVE Published
via MITRE·07:49 PM
Data Sourced
via MITRE·07:49 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
Affected Software
Advisory Published
via GitHub·09:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-38277?
CVE-2024-38277 has a moderate severity level due to potential security implications from key interchangeability.
2
How do I fix CVE-2024-38277?
To fix CVE-2024-38277, upgrade to Moodle versions 4.1.11, 4.2.8, 4.3.5, or 4.4.1 or later.
3
What software is affected by CVE-2024-38277?
CVE-2024-38277 affects Moodle versions before 4.1.11, 4.2.0-beta to 4.2.8, 4.3.0-beta to 4.3.5, and 4.4.0-beta to 4.4.1.
4
What is the impact of CVE-2024-38277?
The impact of CVE-2024-38277 may allow an attacker to exploit the same key for both QR login and auto-login, compromising user accounts.
5
When was CVE-2024-38277 disclosed?
CVE-2024-38277 was disclosed in 2024 but the exact date of disclosure is not stated in the information provided.