REDHAT-BUG-2543604: SSRF
A flaw was found in Moodle's URL downloader. Incorrect handling of IPv4-mapped IPv6 addresses in the host-blocking logic allows an authenticated user to bypass some blocked-host restrictions, resulting in a server-side request forgery (SSRF) risk when the downloader fetches a crafted URL. No further impact beyond partial blocklist bypass has been demonstrated.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated to Moodle and able to supply a crafted URL to the URL downloader.
What restriction can be bypassed?
The flaw bypasses some host-blocking restrictions when an IPv4 address is represented as an IPv4-mapped IPv6 address. The demonstrated impact is limited to a partial blocklist bypass.
What should administrators review while awaiting a fix?
Review which authenticated users can use the URL downloader and the hosts or network locations it can reach. Restrict downloader access and reduce its ability to reach sensitive internal services where possible.