CVE-2024-45690: Moodle: idor when deleting oauth2 linked accounts
A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.
Other sources
Additional checks were required to ensure users can only delete their own OAuth2 linked accounts.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45690?
CVE-2024-45690 has been rated as a high severity vulnerability due to the potential for unauthorized account deletion.
How do I fix CVE-2024-45690?
To resolve CVE-2024-45690, upgrade Moodle to version 4.4.3, 4.3.7, or 4.2.10 or apply the necessary patches.
Which versions of Moodle are affected by CVE-2024-45690?
CVE-2024-45690 affects Moodle versions 4.1.13 and earlier, as well as versions 4.2.0 to 4.2.10, 4.3.0 to 4.3.7, and 4.4.0 to 4.4.3.
What kind of issue does CVE-2024-45690 represent in Moodle?
CVE-2024-45690 represents an authorization flaw allowing users to potentially delete OAuth2-linked accounts of other users.
Is there a workaround for CVE-2024-45690?
There is no official workaround for CVE-2024-45690; updating to the fixed versions is the recommended action.