CVE-2024-43433: Moodle: matrix user/power level management not always working as expected with suspended users
Published Nov 11, 2024
·Updated
A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users.
Affected Software
4 affected componentsFixes available
composer/moodle/moodle>=4.3.0<4.3.6
4.3.6
composer/moodle/moodle>=4.4.0<4.4.2
4.4.2
Moodle Moodle>=4.3.0<4.3.6
Moodle Moodle>=4.4.0<4.4.2
Event History
Nov 11, 2024
CVE Published
via MITRE·12:16 PM
Data Sourced
via MITRE·12:16 PM
DescriptionSeverity
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·03:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-43433?
CVE-2024-43433 has a moderate severity rating due to its impact on user permissions and access control.
2
How do I fix CVE-2024-43433?
To fix CVE-2024-43433, upgrade Moodle to version 4.3.6 or 4.4.2 or later.
3
What are the symptoms of CVE-2024-43433?
The symptoms of CVE-2024-43433 include unauthorized access for suspended users in matrix rooms.
4
Who is affected by CVE-2024-43433?
CVE-2024-43433 affects Moodle installations running versions between 4.3.0 to 4.3.6 and 4.4.0 to 4.4.2.
5
Is there a workaround for CVE-2024-43433 before applying the patch?
Currently, there is no known workaround for CVE-2024-43433; upgrading is the recommended action.