Publish Advisories

GHSA-78fm-qhh8-8858
GHSA-78fm-qhh8-8858
This commit is contained in:
advisory-database[bot]
2023-07-12 00:03:31 +00:00
parent 46df9f9b30
commit 2c3895dd08
2 changed files with 108 additions and 38 deletions
@@ -0,0 +1,108 @@
{
"schema_version": "1.4.0",
"id": "GHSA-78fm-qhh8-8858",
"modified": "2023-07-12T00:02:18Z",
"published": "2022-03-12T00:00:32Z",
"aliases": [
"CVE-2021-32478"
],
"summary": "Moodle reflected XSS",
"details": "The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.10"
},
{
"fixed": "3.10.4"
}
]
}
],
"database_specific": {
"last_known_affected_version_range": "<= 3.10.3"
}
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.9"
},
{
"fixed": "3.9.7"
}
]
}
],
"database_specific": {
"last_known_affected_version_range": "<= 3.9.6"
}
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.8"
},
{
"fixed": "3.8.9"
}
]
}
],
"database_specific": {
"last_known_affected_version_range": "<= 3.8.8"
}
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-32478"
},
{
"type": "WEB",
"url": "https://github.com/moodle/moodle/commit/752ad3d8eb4f9ac22dbf1461aa69d6e0baee503e"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=422314"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2023-07-12T00:02:18Z",
"nvd_published_at": "2022-03-11T18:15:00Z"
}
}
@@ -1,38 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-78fm-qhh8-8858",
"modified": "2022-03-19T00:01:18Z",
"published": "2022-03-12T00:00:32Z",
"aliases": [
"CVE-2021-32478"
],
"details": "The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-32478"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=422314"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-03-11T18:15:00Z"
}
}