The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
References
Link | Resource |
---|---|
https://moodle.org/mod/forum/discuss.php?d=419654 | Patch Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1939051 | Issue Tracking Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AFSNJ7XHVTC52RSRX2GBQFF3VEEAY2MS/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UFH5DDMU5TZ3JT4Q52WMRAHACA5MHIMT/ | Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2021-03-15 15:15
Updated : 2022-08-05 10:51
NVD link : CVE-2021-20283
Mitre link : CVE-2021-20283
JSON object : View
CWE
CWE-862
Missing Authorization
Products Affected
moodle
- moodle
fedoraproject
- fedora