REDHAT-BUG-2359738: High severity moodle vulnerability
A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default this was only available to teachers and managers, on sites with the EQUELLA repository enabled.
Versions affected: 4.5 to 4.5.3, 4.4 to 4.4.7, 4.3 to 4.3.11, 4.1 to 4.1.17 and earlier unsupported versions.
Versions fixed:4.5.4, 4.4.8, 4.3.12 and 4.1.18
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2359738?
The severity of REDHAT-BUG-2359738 is classified as remote code execution, which poses a significant risk to affected installations.
How do I fix REDHAT-BUG-2359738?
To fix REDHAT-BUG-2359738, upgrade to Moodle LMS versions 4.5.4 or later, or apply any available security patches.
Which versions of Moodle LMS are affected by REDHAT-BUG-2359738?
Moodle versions affected by REDHAT-BUG-2359738 include 4.5 to 4.5.3, 4.4 to 4.4.7, 4.3 to 4.3.11, and 4.1 to 4.1.17.
Who is at risk from REDHAT-BUG-2359738?
Users with teacher or manager roles on sites using the EQUELLA repository in the affected versions of Moodle are at risk from REDHAT-BUG-2359738.
What action should I take if I cannot upgrade my Moodle instance due to REDHAT-BUG-2359738?
If upgrading is not possible, consider disabling the EQUELLA repository until a secure version can be implemented to mitigate the risk of REDHAT-BUG-2359738.