REDHAT-BUG-2359735: High severity moodle vulnerability
A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default this was only available to teachers and managers, on sites with the Dropbox repository enabled.
Versions affected: 4.5 to 4.5.3, 4.4 to 4.4.7, 4.3 to 4.3.11, 4.1 to 4.1.17 and earlier unsupported versions.
Versions fixed: 4.5.4, 4.4.8, 4.3.12 and 4.1.18
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2359735?
The severity of REDHAT-BUG-2359735 is classified as a remote code execution risk, which poses significant security threats.
Which versions of Moodle are affected by REDHAT-BUG-2359735?
Moodle versions 4.5 to 4.5.3, 4.4 to 4.4.7, 4.3 to 4.3.11, and 4.1 to 4.1.17, along with earlier unsupported versions, are affected by REDHAT-BUG-2359735.
How do I fix REDHAT-BUG-2359735?
To fix REDHAT-BUG-2359735, it is recommended to upgrade to the latest supported version of Moodle that patches this vulnerability.
What type of vulnerability is REDHAT-BUG-2359735?
REDHAT-BUG-2359735 is categorized as a remote code execution vulnerability, allowing potential attackers to execute arbitrary code.
Who is primarily at risk from REDHAT-BUG-2359735?
Primarily, teachers and managers on sites with the Dropbox repository enabled in Moodle are at risk from REDHAT-BUG-2359735.