Publish Advisories

GHSA-2jrm-gww7-wch2
GHSA-58fm-v4pr-jh8p
GHSA-6r76-f8c8-fh7p
GHSA-g58x-p3pj-rg52
GHSA-pgm5-cr62-prxq
GHSA-wwv7-h477-wrv7
GHSA-xp2f-9mx3-3c6p
GHSA-2jxg-mv2m-j4r7
GHSA-92vh-mr2w-j2cr
GHSA-gp4w-f57r-9rx3
GHSA-m37g-mwcg-7j7v
GHSA-wr6q-xv23-rfq9
GHSA-jqgr-gh62-jf53
GHSA-xqcf-vgqc-pcmg
GHSA-2jrm-gww7-wch2
GHSA-6r76-f8c8-fh7p
GHSA-wwv7-h477-wrv7
GHSA-2jxg-mv2m-j4r7
GHSA-92vh-mr2w-j2cr
GHSA-gp4w-f57r-9rx3
GHSA-m37g-mwcg-7j7v
GHSA-wr6q-xv23-rfq9
GHSA-jqgr-gh62-jf53
This commit is contained in:
advisory-database[bot]
2024-04-23 23:37:58 +00:00
parent a15c7929f4
commit a682f83aa9
23 changed files with 1166 additions and 387 deletions
@@ -0,0 +1,119 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2jrm-gww7-wch2",
"modified": "2024-04-23T23:37:33Z",
"published": "2022-05-24T17:40:31Z",
"aliases": [
"CVE-2021-20187"
],
"summary": "Moodle Arbitrary PHP code execution by site admins via Shibboleth configuration",
"details": "It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.5"
},
{
"fixed": "3.5.16"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.8"
},
{
"fixed": "3.8.7"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.9"
},
{
"fixed": "3.9.4"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.10"
},
{
"fixed": "3.10.1"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20187"
},
{
"type": "PACKAGE",
"url": "https://github.com/moodle/moodle"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=417171"
}
],
"database_specific": {
"cwe_ids": [
"CWE-829",
"CWE-94"
],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-04-23T23:37:33Z",
"nvd_published_at": "2021-01-28T19:15:00Z"
}
}
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-58fm-v4pr-jh8p",
"modified": "2022-05-17T03:38:33Z",
"modified": "2024-04-23T23:36:24Z",
"published": "2022-05-17T03:38:33Z",
"aliases": [
"CVE-2016-9187"
],
"summary": "Moodle Unrestricted file upload vulnerability",
"details": "Unrestricted file upload vulnerability in the double extension support in the \"image\" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.",
"severity": [
{
@@ -14,13 +15,35 @@
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "2.0.1"
},
{
"last_affected": "3.2.1"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2016-9187"
},
{
"type": "PACKAGE",
"url": "https://github.com/moodle/moodle"
},
{
"type": "WEB",
"url": "https://packetstormsecurity.com/files/139466/Moodle-CMS-3.1.2-Cross-Site-Scripting-File-Upload.html"
@@ -35,8 +58,8 @@
"CWE-434"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-04-23T23:36:24Z",
"nvd_published_at": "2016-11-04T10:59:00Z"
}
}
@@ -0,0 +1,84 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6r76-f8c8-fh7p",
"modified": "2024-04-23T23:36:08Z",
"published": "2022-05-17T03:03:00Z",
"aliases": [
"CVE-2017-2578"
],
"summary": "Moodle Cross-site Scripting in assignment submission page",
"details": "In Moodle 3.x, there is Cross-site Scripting in the assignment submission page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.1"
},
{
"fixed": "3.1.4"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.2"
},
{
"fixed": "3.2.1"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-2578"
},
{
"type": "PACKAGE",
"url": "https://github.com/moodle/moodle"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=345915"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/95647"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-04-23T23:36:08Z",
"nvd_published_at": "2017-01-20T08:59:00Z"
}
}
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g58x-p3pj-rg52",
"modified": "2022-05-17T03:03:04Z",
"modified": "2024-04-23T23:36:18Z",
"published": "2022-05-17T03:03:04Z",
"aliases": [
"CVE-2016-5012"
],
"summary": "Moodle Glossary search displays entries without checking user permissions to view them",
"details": "In Moodle 3.x, glossary search displays entries without checking user permissions to view them.",
"severity": [
{
@@ -14,13 +15,35 @@
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.1"
},
{
"fixed": "3.1.1"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2016-5012"
},
{
"type": "PACKAGE",
"url": "https://github.com/moodle/moodle"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=336697"
@@ -35,8 +58,8 @@
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-04-23T23:36:18Z",
"nvd_published_at": "2017-01-20T08:59:00Z"
}
}
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pgm5-cr62-prxq",
"modified": "2022-08-02T00:00:24Z",
"modified": "2024-04-23T23:36:44Z",
"published": "2022-07-26T00:00:29Z",
"aliases": [
"CVE-2022-35650"
],
"summary": "Moodle Arbitrary file read when importing lesson questions",
"details": "The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.",
"severity": [
{
@@ -14,7 +15,63 @@
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.9"
},
{
"fixed": "3.9.15"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.11"
},
{
"fixed": "3.11.8"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.0"
},
{
"fixed": "4.0.2"
}
]
}
]
}
],
"references": [
{
@@ -25,6 +82,10 @@
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2106274"
},
{
"type": "PACKAGE",
"url": "https://github.com/moodle/moodle"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6MOKYVRNFNAODP2XSMGJ5CRDUZCZKAR3"
@@ -47,8 +108,8 @@
"CWE-20"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-04-23T23:36:44Z",
"nvd_published_at": "2022-07-25T16:15:00Z"
}
}
@@ -0,0 +1,116 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wwv7-h477-wrv7",
"modified": "2024-04-23T23:37:10Z",
"published": "2022-07-26T00:00:29Z",
"aliases": [
"CVE-2022-35651"
],
"summary": "Moodle Stored XSS and blind SSRF possible via SCORM track details",
"details": "A stored Cross-site Scripting (XSS) and blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.9"
},
{
"fixed": "3.9.15"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.11"
},
{
"fixed": "3.11.8"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.0"
},
{
"fixed": "4.0.2"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-35651"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2106275"
},
{
"type": "PACKAGE",
"url": "https://github.com/moodle/moodle"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6MOKYVRNFNAODP2XSMGJ5CRDUZCZKAR3"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MTKUSFPSYFINSQFSOHDQIDVE6FWBEU6V"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=436458"
},
{
"type": "WEB",
"url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-71921"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79",
"CWE-918"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-04-23T23:37:10Z",
"nvd_published_at": "2022-07-25T16:15:00Z"
}
}
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xp2f-9mx3-3c6p",
"modified": "2022-08-02T00:00:24Z",
"modified": "2024-04-23T23:36:31Z",
"published": "2022-07-26T00:00:29Z",
"aliases": [
"CVE-2022-35649"
],
"summary": "Moodle PostScript Code Injection",
"details": "The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk for sites running GhostScript versions older than 9.50. Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.",
"severity": [
{
@@ -14,7 +15,63 @@
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.9"
},
{
"fixed": "3.9.15"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.11"
},
{
"fixed": "3.11.8"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.0"
},
{
"fixed": "4.0.2"
}
]
}
]
}
],
"references": [
{
@@ -25,6 +82,10 @@
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2106273"
},
{
"type": "PACKAGE",
"url": "https://github.com/moodle/moodle"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6MOKYVRNFNAODP2XSMGJ5CRDUZCZKAR3"
@@ -47,8 +108,8 @@
"CWE-20"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-04-23T23:36:31Z",
"nvd_published_at": "2022-07-25T16:15:00Z"
}
}
@@ -0,0 +1,99 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2jxg-mv2m-j4r7",
"modified": "2024-04-23T23:37:27Z",
"published": "2022-09-30T00:00:30Z",
"aliases": [
"CVE-2021-40693"
],
"summary": "Moodle type juggling vulnerability",
"details": "An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.9"
},
{
"fixed": "3.9.10"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.10"
},
{
"fixed": "3.10.7"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.11"
},
{
"fixed": "3.11.3"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-40693"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2043417"
},
{
"type": "PACKAGE",
"url": "https://github.com/moodle/moodle"
}
],
"database_specific": {
"cwe_ids": [
"CWE-287"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-04-23T23:37:27Z",
"nvd_published_at": "2022-09-29T03:15:00Z"
}
}
@@ -0,0 +1,99 @@
{
"schema_version": "1.4.0",
"id": "GHSA-92vh-mr2w-j2cr",
"modified": "2024-04-23T23:35:55Z",
"published": "2022-09-30T00:00:30Z",
"aliases": [
"CVE-2021-40691"
],
"summary": "Moodle Improper Authentication",
"details": "A session hijack risk was identified in the Shibboleth authentication plugin.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.9"
},
{
"fixed": "3.9.10"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.10"
},
{
"fixed": "3.10.7"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.11"
},
{
"fixed": "3.11.3"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-40691"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2043411"
},
{
"type": "PACKAGE",
"url": "https://github.com/moodle/moodle"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-04-23T23:35:55Z",
"nvd_published_at": "2022-09-29T03:15:00Z"
}
}
@@ -0,0 +1,99 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gp4w-f57r-9rx3",
"modified": "2024-04-23T23:37:17Z",
"published": "2022-09-30T00:00:29Z",
"aliases": [
"CVE-2021-40695"
],
"summary": "Moodle Exposure of Sensitive Information to an Unauthorized Actor",
"details": "It was possible for a student to view their quiz grade before it had been released, using a quiz web service.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.11"
},
{
"fixed": "3.11.3"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.10"
},
{
"fixed": "3.10.7"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.9"
},
{
"fixed": "3.9.10"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-40695"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2043424"
},
{
"type": "PACKAGE",
"url": "https://github.com/moodle/moodle"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-04-23T23:37:17Z",
"nvd_published_at": "2022-09-29T03:15:00Z"
}
}
@@ -0,0 +1,99 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m37g-mwcg-7j7v",
"modified": "2024-04-23T23:37:22Z",
"published": "2022-09-30T00:00:29Z",
"aliases": [
"CVE-2021-40694"
],
"summary": "Moodle Improper Encoding or Escaping of Output",
"details": "Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.9"
},
{
"fixed": "3.9.10"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.10"
},
{
"fixed": "3.10.7"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.11"
},
{
"fixed": "3.11.3"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-40694"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2043421"
},
{
"type": "PACKAGE",
"url": "https://github.com/moodle/moodle"
}
],
"database_specific": {
"cwe_ids": [
"CWE-116"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-04-23T23:37:22Z",
"nvd_published_at": "2022-09-29T03:15:00Z"
}
}
@@ -0,0 +1,99 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wr6q-xv23-rfq9",
"modified": "2024-04-23T23:36:01Z",
"published": "2022-09-30T00:00:30Z",
"aliases": [
"CVE-2021-40692"
],
"summary": "Moodle Incorrect Authorization",
"details": "Insufficient capability checks made it possible for teachers to download users outside of their courses.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.11"
},
{
"fixed": "3.11.3"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.10"
},
{
"fixed": "3.10.7"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.9"
},
{
"fixed": "3.9.10"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-40692"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2043414"
},
{
"type": "PACKAGE",
"url": "https://github.com/moodle/moodle"
}
],
"database_specific": {
"cwe_ids": [
"CWE-863"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-04-23T23:36:01Z",
"nvd_published_at": "2022-09-29T03:15:00Z"
}
}
@@ -0,0 +1,103 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jqgr-gh62-jf53",
"modified": "2024-04-23T23:35:47Z",
"published": "2022-10-01T00:00:20Z",
"aliases": [
"CVE-2022-40313"
],
"summary": "Moodle Stored Cross-site Scripting and page denial of service",
"details": "Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an Cross-site Scripting risk or a page failing to load.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.9"
},
{
"fixed": "3.9.17"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.11"
},
{
"fixed": "3.11.10"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.0"
},
{
"fixed": "4.0.4"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40313"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2128146"
},
{
"type": "PACKAGE",
"url": "https://github.com/moodle/moodle"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=438392"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-04-23T23:35:47Z",
"nvd_published_at": "2022-09-30T17:15:00Z"
}
}
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xqcf-vgqc-pcmg",
"modified": "2022-12-01T18:30:48Z",
"modified": "2024-04-23T23:36:13Z",
"published": "2022-11-25T21:30:26Z",
"aliases": [
"CVE-2022-45152"
],
"summary": "Moodle blind Server-Side Request Forgery (SSRF) vulnerability in LTI provider library",
"details": "A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems. This vulnerability allows a remote attacker to perform SSRF attacks.",
"severity": [
{
@@ -14,7 +15,63 @@
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.9"
},
{
"fixed": "3.9.18"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.11"
},
{
"fixed": "3.11.11"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.0"
},
{
"fixed": "4.0.5"
}
]
}
]
}
],
"references": [
{
@@ -25,6 +82,10 @@
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2142775"
},
{
"type": "PACKAGE",
"url": "https://github.com/moodle/moodle"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2DHYIIAUXUBHMBEDYU7TYNZXEN2W2SA2"
@@ -51,8 +112,8 @@
"CWE-918"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-04-23T23:36:13Z",
"nvd_published_at": "2022-11-25T19:15:00Z"
}
}
@@ -1,39 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2jrm-gww7-wch2",
"modified": "2022-10-22T12:00:27Z",
"published": "2022-05-24T17:40:31Z",
"aliases": [
"CVE-2021-20187"
],
"details": "It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20187"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=417171"
}
],
"database_specific": {
"cwe_ids": [
"CWE-829",
"CWE-94"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2021-01-28T19:15:00Z"
}
}
@@ -1,42 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6r76-f8c8-fh7p",
"modified": "2022-05-17T03:03:00Z",
"published": "2022-05-17T03:03:00Z",
"aliases": [
"CVE-2017-2578"
],
"details": "In Moodle 3.x, there is XSS in the assignment submission page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-2578"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=345915"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/95647"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2017-01-20T08:59:00Z"
}
}
@@ -1,54 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wwv7-h477-wrv7",
"modified": "2022-07-30T00:00:38Z",
"published": "2022-07-26T00:00:29Z",
"aliases": [
"CVE-2022-35651"
],
"details": "A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-35651"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2106275"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6MOKYVRNFNAODP2XSMGJ5CRDUZCZKAR3"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MTKUSFPSYFINSQFSOHDQIDVE6FWBEU6V"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=436458"
},
{
"type": "WEB",
"url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-71921"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-07-25T16:15:00Z"
}
}
@@ -1,38 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2jxg-mv2m-j4r7",
"modified": "2022-10-04T00:00:20Z",
"published": "2022-09-30T00:00:30Z",
"aliases": [
"CVE-2021-40693"
],
"details": "An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-40693"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2043417"
}
],
"database_specific": {
"cwe_ids": [
"CWE-287"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-09-29T03:15:00Z"
}
}
@@ -1,38 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-92vh-mr2w-j2cr",
"modified": "2022-10-04T00:00:25Z",
"published": "2022-09-30T00:00:30Z",
"aliases": [
"CVE-2021-40691"
],
"details": "A session hijack risk was identified in the Shibboleth authentication plugin.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-40691"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2043411"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-09-29T03:15:00Z"
}
}
@@ -1,38 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gp4w-f57r-9rx3",
"modified": "2022-10-04T00:00:24Z",
"published": "2022-09-30T00:00:29Z",
"aliases": [
"CVE-2021-40695"
],
"details": "It was possible for a student to view their quiz grade before it had been released, using a quiz web service.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-40695"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2043424"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-09-29T03:15:00Z"
}
}

Some files were not shown because too many files have changed in this diff Show More