First published: Tue Sep 20 2022(Updated: )
Severity/Risk: Serious Versions affected: 4.0 to 4.0.3, 3.11 to 3.11.9, 3.9 to 3.9.16 and earlier unsupported versions Versions fixed: 4.0.4, 3.11.10 and 3.9.17 Reported by: Paul Holden CVE identifier: <a href="https://access.redhat.com/security/cve/CVE-2022-40314">CVE-2022-40314</a> Changes (master): <a href="http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-75405">http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-75405</a> Tracker issue: MDL-75405 Remote code execution risk when restoring malformed backup file from Moodle 1.9
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle | >=3.9<3.9.16>=3.11<3.11.9>=4.0<4.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2128147 is classified as Serious.
Moodle versions affected by REDHAT-BUG-2128147 include 4.0 to 4.0.3, 3.11 to 3.11.9, and 3.9 to 3.9.16.
To resolve REDHAT-BUG-2128147, upgrade to Moodle versions 4.0.4, 3.11.10, or 3.9.17.
Yes, REDHAT-BUG-2128147 is associated with the CVE identifier CVE-2022-40314.
REDHAT-BUG-2128147 was reported by Paul Holden.