From fc106d221f6132f2012a46707ada63dc25c520a2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 23 Apr 2024 23:40:02 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-4qxc-qxrp-33cw.json | 119 ++++++++++++++++ .../GHSA-5wjh-v7c8-wrhx.json | 118 ++++++++++++++++ .../GHSA-rvmc-8gmg-ggqr.json | 118 ++++++++++++++++ .../GHSA-vrpr-2xxx-g444.json | 31 ++++- .../GHSA-4w4j-9533-82qg.json | 99 +++++++++++++ .../GHSA-774q-wfcp-vc2q.json | 85 ++++++++++++ .../GHSA-c3j6-33r4-89q3.json | 119 ++++++++++++++++ .../GHSA-g39c-mccf-rxjv.json | 103 ++++++++++++++ .../GHSA-grj4-g57c-9xmv.json | 130 ++++++++++++++++++ .../GHSA-h8m4-h385-qhqv.json | 118 ++++++++++++++++ .../GHSA-j8wr-7xxj-c2fr.json | 122 ++++++++++++++++ .../GHSA-m98q-q59p-r9fv.json | 103 ++++++++++++++ .../GHSA-mgfp-qcf2-pw3m.json | 36 ++++- .../GHSA-mm73-86f9-5x5c.json | 99 +++++++++++++ .../GHSA-q6vw-27c6-jv9c.json | 65 +++++++++ .../GHSA-4qxc-qxrp-33cw.json | 39 ------ .../GHSA-5wjh-v7c8-wrhx.json | 38 ----- .../GHSA-rvmc-8gmg-ggqr.json | 38 ----- .../GHSA-4w4j-9533-82qg.json | 35 ----- .../GHSA-774q-wfcp-vc2q.json | 39 ------ .../GHSA-c3j6-33r4-89q3.json | 39 ------ .../GHSA-g39c-mccf-rxjv.json | 42 ------ .../GHSA-grj4-g57c-9xmv.json | 47 ------- .../GHSA-h8m4-h385-qhqv.json | 35 ----- .../GHSA-j8wr-7xxj-c2fr.json | 39 ------ .../GHSA-m98q-q59p-r9fv.json | 39 ------ .../GHSA-mm73-86f9-5x5c.json | 35 ----- .../GHSA-q6vw-27c6-jv9c.json | 39 ------ 28 files changed, 1456 insertions(+), 513 deletions(-) create mode 100644 advisories/github-reviewed/2022/03/GHSA-4qxc-qxrp-33cw/GHSA-4qxc-qxrp-33cw.json create mode 100644 advisories/github-reviewed/2022/03/GHSA-5wjh-v7c8-wrhx/GHSA-5wjh-v7c8-wrhx.json create mode 100644 advisories/github-reviewed/2022/03/GHSA-rvmc-8gmg-ggqr/GHSA-rvmc-8gmg-ggqr.json rename advisories/{unreviewed => github-reviewed}/2022/03/GHSA-vrpr-2xxx-g444/GHSA-vrpr-2xxx-g444.json (59%) create mode 100644 advisories/github-reviewed/2022/05/GHSA-4w4j-9533-82qg/GHSA-4w4j-9533-82qg.json create mode 100644 advisories/github-reviewed/2022/05/GHSA-774q-wfcp-vc2q/GHSA-774q-wfcp-vc2q.json create mode 100644 advisories/github-reviewed/2022/05/GHSA-c3j6-33r4-89q3/GHSA-c3j6-33r4-89q3.json create mode 100644 advisories/github-reviewed/2022/05/GHSA-g39c-mccf-rxjv/GHSA-g39c-mccf-rxjv.json create mode 100644 advisories/github-reviewed/2022/05/GHSA-grj4-g57c-9xmv/GHSA-grj4-g57c-9xmv.json create mode 100644 advisories/github-reviewed/2022/05/GHSA-h8m4-h385-qhqv/GHSA-h8m4-h385-qhqv.json create mode 100644 advisories/github-reviewed/2022/05/GHSA-j8wr-7xxj-c2fr/GHSA-j8wr-7xxj-c2fr.json create mode 100644 advisories/github-reviewed/2022/05/GHSA-m98q-q59p-r9fv/GHSA-m98q-q59p-r9fv.json rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-mgfp-qcf2-pw3m/GHSA-mgfp-qcf2-pw3m.json (50%) create mode 100644 advisories/github-reviewed/2022/05/GHSA-mm73-86f9-5x5c/GHSA-mm73-86f9-5x5c.json create mode 100644 advisories/github-reviewed/2022/05/GHSA-q6vw-27c6-jv9c/GHSA-q6vw-27c6-jv9c.json delete mode 100644 advisories/unreviewed/2022/03/GHSA-4qxc-qxrp-33cw/GHSA-4qxc-qxrp-33cw.json delete mode 100644 advisories/unreviewed/2022/03/GHSA-5wjh-v7c8-wrhx/GHSA-5wjh-v7c8-wrhx.json delete mode 100644 advisories/unreviewed/2022/03/GHSA-rvmc-8gmg-ggqr/GHSA-rvmc-8gmg-ggqr.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-4w4j-9533-82qg/GHSA-4w4j-9533-82qg.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-774q-wfcp-vc2q/GHSA-774q-wfcp-vc2q.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-c3j6-33r4-89q3/GHSA-c3j6-33r4-89q3.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-g39c-mccf-rxjv/GHSA-g39c-mccf-rxjv.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-grj4-g57c-9xmv/GHSA-grj4-g57c-9xmv.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-h8m4-h385-qhqv/GHSA-h8m4-h385-qhqv.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-j8wr-7xxj-c2fr/GHSA-j8wr-7xxj-c2fr.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-m98q-q59p-r9fv/GHSA-m98q-q59p-r9fv.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-mm73-86f9-5x5c/GHSA-mm73-86f9-5x5c.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-q6vw-27c6-jv9c/GHSA-q6vw-27c6-jv9c.json diff --git a/advisories/github-reviewed/2022/03/GHSA-4qxc-qxrp-33cw/GHSA-4qxc-qxrp-33cw.json b/advisories/github-reviewed/2022/03/GHSA-4qxc-qxrp-33cw/GHSA-4qxc-qxrp-33cw.json new file mode 100644 index 00000000000..e3083500312 --- /dev/null +++ b/advisories/github-reviewed/2022/03/GHSA-4qxc-qxrp-33cw/GHSA-4qxc-qxrp-33cw.json @@ -0,0 +1,119 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qxc-qxrp-33cw", + "modified": "2024-04-23T23:39:07Z", + "published": "2022-03-12T00:00:33Z", + "aliases": [ + "CVE-2021-32476" + ], + "summary": "Moodle denial-of-service risk in the draft files area", + "details": "A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.10" + }, + { + "fixed": "3.10.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.9" + }, + { + "fixed": "3.9.7" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.8" + }, + { + "fixed": "3.8.9" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.5.17" + }, + { + "fixed": "3.5.18" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-32476" + }, + { + "type": "PACKAGE", + "url": "https://github.com/moodle/moodle" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=422310" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400", + "CWE-770" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-04-23T23:39:07Z", + "nvd_published_at": "2022-03-11T18:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/03/GHSA-5wjh-v7c8-wrhx/GHSA-5wjh-v7c8-wrhx.json b/advisories/github-reviewed/2022/03/GHSA-5wjh-v7c8-wrhx/GHSA-5wjh-v7c8-wrhx.json new file mode 100644 index 00000000000..81a73e8e710 --- /dev/null +++ b/advisories/github-reviewed/2022/03/GHSA-5wjh-v7c8-wrhx/GHSA-5wjh-v7c8-wrhx.json @@ -0,0 +1,118 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wjh-v7c8-wrhx", + "modified": "2024-04-23T23:39:01Z", + "published": "2022-03-12T00:00:33Z", + "aliases": [ + "CVE-2021-32475" + ], + "summary": "Moodle stored Cross-site Scripting ", + "details": "ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.5" + }, + { + "fixed": "3.5.18" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.8" + }, + { + "fixed": "3.8.9" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.9" + }, + { + "fixed": "3.9.7" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.10" + }, + { + "fixed": "3.10.4" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-32475" + }, + { + "type": "PACKAGE", + "url": "https://github.com/moodle/moodle" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=422309" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-23T23:39:01Z", + "nvd_published_at": "2022-03-11T18:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/03/GHSA-rvmc-8gmg-ggqr/GHSA-rvmc-8gmg-ggqr.json b/advisories/github-reviewed/2022/03/GHSA-rvmc-8gmg-ggqr/GHSA-rvmc-8gmg-ggqr.json new file mode 100644 index 00000000000..dec198014cd --- /dev/null +++ b/advisories/github-reviewed/2022/03/GHSA-rvmc-8gmg-ggqr/GHSA-rvmc-8gmg-ggqr.json @@ -0,0 +1,118 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvmc-8gmg-ggqr", + "modified": "2024-04-23T23:38:48Z", + "published": "2022-03-12T00:00:32Z", + "aliases": [ + "CVE-2021-32474" + ], + "summary": "Moodle Blind SQL injection possible via MNet authentication", + "details": "An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required site administrator access or access to the keypair. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.10" + }, + { + "fixed": "3.10.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.9" + }, + { + "fixed": "3.9.7" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.8" + }, + { + "fixed": "3.8.9" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.5" + }, + { + "fixed": "3.5.18" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-32474" + }, + { + "type": "PACKAGE", + "url": "https://github.com/moodle/moodle" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=422308" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-04-23T23:38:48Z", + "nvd_published_at": "2022-03-11T18:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/03/GHSA-vrpr-2xxx-g444/GHSA-vrpr-2xxx-g444.json b/advisories/github-reviewed/2022/03/GHSA-vrpr-2xxx-g444/GHSA-vrpr-2xxx-g444.json similarity index 59% rename from advisories/unreviewed/2022/03/GHSA-vrpr-2xxx-g444/GHSA-vrpr-2xxx-g444.json rename to advisories/github-reviewed/2022/03/GHSA-vrpr-2xxx-g444/GHSA-vrpr-2xxx-g444.json index 23fbd62d000..f66cedd8b09 100644 --- a/advisories/unreviewed/2022/03/GHSA-vrpr-2xxx-g444/GHSA-vrpr-2xxx-g444.json +++ b/advisories/github-reviewed/2022/03/GHSA-vrpr-2xxx-g444/GHSA-vrpr-2xxx-g444.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-vrpr-2xxx-g444", - "modified": "2022-03-19T00:01:18Z", + "modified": "2024-04-23T23:38:53Z", "published": "2022-03-12T00:00:32Z", "aliases": [ "CVE-2021-32477" ], + "summary": "Moodle Exposure of Sensitive Information to an Unauthorized Actor", "details": "The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affected.", "severity": [ { @@ -14,13 +15,35 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.10" + }, + { + "fixed": "3.10.4" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-32477" }, + { + "type": "PACKAGE", + "url": "https://github.com/moodle/moodle" + }, { "type": "WEB", "url": "https://moodle.org/mod/forum/discuss.php?d=422313" @@ -32,8 +55,8 @@ "CWE-862" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-04-23T23:38:53Z", "nvd_published_at": "2022-03-11T18:15:00Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-4w4j-9533-82qg/GHSA-4w4j-9533-82qg.json b/advisories/github-reviewed/2022/05/GHSA-4w4j-9533-82qg/GHSA-4w4j-9533-82qg.json new file mode 100644 index 00000000000..9f6740b1800 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-4w4j-9533-82qg/GHSA-4w4j-9533-82qg.json @@ -0,0 +1,99 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4w4j-9533-82qg", + "modified": "2024-04-23T23:37:54Z", + "published": "2022-05-24T17:35:32Z", + "aliases": [ + "CVE-2020-25631" + ], + "summary": "Moodle Cross-site Scripting (XSS)", + "details": "A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScript in a book's chapter title, which was not escaped on the \"Add new chapter\" page. This is fixed in 3.9.2, 3.8.5 and 3.7.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.9" + }, + { + "fixed": "3.9.2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.8" + }, + { + "fixed": "3.8.5" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.7" + }, + { + "fixed": "3.7.8" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25631" + }, + { + "type": "PACKAGE", + "url": "https://github.com/moodle/moodle" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=410843" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-23T23:37:54Z", + "nvd_published_at": "2020-12-08T01:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-774q-wfcp-vc2q/GHSA-774q-wfcp-vc2q.json b/advisories/github-reviewed/2022/05/GHSA-774q-wfcp-vc2q/GHSA-774q-wfcp-vc2q.json new file mode 100644 index 00000000000..2202c6759e8 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-774q-wfcp-vc2q/GHSA-774q-wfcp-vc2q.json @@ -0,0 +1,85 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-774q-wfcp-vc2q", + "modified": "2024-04-23T23:37:43Z", + "published": "2022-05-24T17:11:48Z", + "aliases": [ + "CVE-2019-14883" + ], + "summary": "Moodle Email media URL tokens were not checking for user status", + "details": "A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their token.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.6" + }, + { + "fixed": "3.6.7" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.7" + }, + { + "fixed": "3.7.3" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-14883" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14883" + }, + { + "type": "PACKAGE", + "url": "https://github.com/moodle/moodle" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=393586#p1586750" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285", + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-23T23:37:43Z", + "nvd_published_at": "2020-03-18T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-c3j6-33r4-89q3/GHSA-c3j6-33r4-89q3.json b/advisories/github-reviewed/2022/05/GHSA-c3j6-33r4-89q3/GHSA-c3j6-33r4-89q3.json new file mode 100644 index 00000000000..c497a519a51 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-c3j6-33r4-89q3/GHSA-c3j6-33r4-89q3.json @@ -0,0 +1,119 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3j6-33r4-89q3", + "modified": "2024-04-23T23:38:01Z", + "published": "2022-05-24T17:40:31Z", + "aliases": [ + "CVE-2021-20185" + ], + "summary": "Moodle Client side denial of service via personal message", + "details": "It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which could result in client-side (browser) denial of service for users receiving very large messages.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.5" + }, + { + "fixed": "3.5.16" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.8" + }, + { + "fixed": "3.8.7" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.9" + }, + { + "fixed": "3.9.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.10" + }, + { + "fixed": "3.10.1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20185" + }, + { + "type": "PACKAGE", + "url": "https://github.com/moodle/moodle" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=417168" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400", + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-23T23:38:01Z", + "nvd_published_at": "2021-01-28T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-g39c-mccf-rxjv/GHSA-g39c-mccf-rxjv.json b/advisories/github-reviewed/2022/05/GHSA-g39c-mccf-rxjv/GHSA-g39c-mccf-rxjv.json new file mode 100644 index 00000000000..70048e23479 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-g39c-mccf-rxjv/GHSA-g39c-mccf-rxjv.json @@ -0,0 +1,103 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g39c-mccf-rxjv", + "modified": "2024-04-23T23:38:42Z", + "published": "2022-05-24T19:21:10Z", + "aliases": [ + "CVE-2021-43560" + ], + "summary": "Moodle Insecure direct object reference (IDOR) in a calendar web service", + "details": "A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.9" + }, + { + "fixed": "3.9.11" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.10" + }, + { + "fixed": "3.10.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.11" + }, + { + "fixed": "3.11.4" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-43560" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2021519" + }, + { + "type": "PACKAGE", + "url": "https://github.com/moodle/moodle" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=429100" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-668" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-23T23:38:42Z", + "nvd_published_at": "2021-11-22T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-grj4-g57c-9xmv/GHSA-grj4-g57c-9xmv.json b/advisories/github-reviewed/2022/05/GHSA-grj4-g57c-9xmv/GHSA-grj4-g57c-9xmv.json new file mode 100644 index 00000000000..796130896fa --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-grj4-g57c-9xmv/GHSA-grj4-g57c-9xmv.json @@ -0,0 +1,130 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grj4-g57c-9xmv", + "modified": "2024-04-23T23:38:11Z", + "published": "2022-05-24T17:44:37Z", + "aliases": [ + "CVE-2021-20282" + ], + "summary": "Moodle Bypass email verification secret when confirming account registration", + "details": "When creating a user account, it was possible to verify the account without having access to the verification email link/secret in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.5" + }, + { + "fixed": "3.5.17" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.8" + }, + { + "fixed": "3.8.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.9" + }, + { + "fixed": "3.9.5" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.10" + }, + { + "fixed": "3.10.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20282" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1939046" + }, + { + "type": "PACKAGE", + "url": "https://github.com/moodle/moodle" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AFSNJ7XHVTC52RSRX2GBQFF3VEEAY2MS" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UFH5DDMU5TZ3JT4Q52WMRAHACA5MHIMT" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=419653" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-23T23:38:11Z", + "nvd_published_at": "2021-03-15T22:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-h8m4-h385-qhqv/GHSA-h8m4-h385-qhqv.json b/advisories/github-reviewed/2022/05/GHSA-h8m4-h385-qhqv/GHSA-h8m4-h385-qhqv.json new file mode 100644 index 00000000000..64e1c8682e8 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-h8m4-h385-qhqv/GHSA-h8m4-h385-qhqv.json @@ -0,0 +1,118 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8m4-h385-qhqv", + "modified": "2024-04-23T23:38:06Z", + "published": "2022-05-24T17:40:31Z", + "aliases": [ + "CVE-2021-20186" + ], + "summary": "Moodle Cross-site Scripting", + "details": "It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.10" + }, + { + "fixed": "3.10.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.9" + }, + { + "fixed": "3.9.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.8" + }, + { + "fixed": "3.8.7" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.5" + }, + { + "fixed": "3.5.16" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20186" + }, + { + "type": "PACKAGE", + "url": "https://github.com/moodle/moodle" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=417170" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-23T23:38:06Z", + "nvd_published_at": "2021-01-28T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-j8wr-7xxj-c2fr/GHSA-j8wr-7xxj-c2fr.json b/advisories/github-reviewed/2022/05/GHSA-j8wr-7xxj-c2fr/GHSA-j8wr-7xxj-c2fr.json new file mode 100644 index 00000000000..501d0aad622 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-j8wr-7xxj-c2fr/GHSA-j8wr-7xxj-c2fr.json @@ -0,0 +1,122 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8wr-7xxj-c2fr", + "modified": "2024-04-23T23:39:12Z", + "published": "2022-05-24T16:48:40Z", + "aliases": [ + "CVE-2019-10134" + ], + "summary": "Moodle Private files uploaded via incoming mail processing could bypass quota restrictions", + "details": "A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.6" + }, + { + "fixed": "3.6.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.5" + }, + { + "fixed": "3.5.6" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.4" + }, + { + "fixed": "3.4.9" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.1" + }, + { + "fixed": "3.1.18" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-10134" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10134" + }, + { + "type": "PACKAGE", + "url": "https://github.com/moodle/moodle" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=386524" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-23T23:39:12Z", + "nvd_published_at": "2019-06-26T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-m98q-q59p-r9fv/GHSA-m98q-q59p-r9fv.json b/advisories/github-reviewed/2022/05/GHSA-m98q-q59p-r9fv/GHSA-m98q-q59p-r9fv.json new file mode 100644 index 00000000000..59210e92ab6 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-m98q-q59p-r9fv/GHSA-m98q-q59p-r9fv.json @@ -0,0 +1,103 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m98q-q59p-r9fv", + "modified": "2024-04-23T23:37:37Z", + "published": "2022-05-24T17:11:48Z", + "aliases": [ + "CVE-2019-14882" + ], + "summary": "Moodle open redirect vulnerability", + "details": "A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed in the Lesson edit page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.5" + }, + { + "fixed": "3.5.9" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.6" + }, + { + "fixed": "3.6.7" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.7" + }, + { + "fixed": "3.7.3" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-14882" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14882" + }, + { + "type": "PACKAGE", + "url": "https://github.com/moodle/moodle" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=393585#p1586747" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-23T23:37:37Z", + "nvd_published_at": "2020-03-18T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-mgfp-qcf2-pw3m/GHSA-mgfp-qcf2-pw3m.json b/advisories/github-reviewed/2022/05/GHSA-mgfp-qcf2-pw3m/GHSA-mgfp-qcf2-pw3m.json similarity index 50% rename from advisories/unreviewed/2022/05/GHSA-mgfp-qcf2-pw3m/GHSA-mgfp-qcf2-pw3m.json rename to advisories/github-reviewed/2022/05/GHSA-mgfp-qcf2-pw3m/GHSA-mgfp-qcf2-pw3m.json index c4f26d3bd99..eef2b78239e 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgfp-qcf2-pw3m/GHSA-mgfp-qcf2-pw3m.json +++ b/advisories/github-reviewed/2022/05/GHSA-mgfp-qcf2-pw3m/GHSA-mgfp-qcf2-pw3m.json @@ -1,23 +1,49 @@ { "schema_version": "1.4.0", "id": "GHSA-mgfp-qcf2-pw3m", - "modified": "2022-05-24T17:35:32Z", + "modified": "2024-04-23T23:37:49Z", "published": "2022-05-24T17:35:32Z", "aliases": [ "CVE-2020-25627" ], + "summary": "Moodle stored Cross-site Scripting (XSS)", "details": "The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ - + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.9" + }, + { + "fixed": "3.9.2" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25627" }, + { + "type": "PACKAGE", + "url": "https://github.com/moodle/moodle" + }, { "type": "WEB", "url": "https://moodle.org/mod/forum/discuss.php?d=410839" @@ -28,8 +54,8 @@ "CWE-79" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-04-23T23:37:48Z", "nvd_published_at": "2020-12-09T01:15:00Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-mm73-86f9-5x5c/GHSA-mm73-86f9-5x5c.json b/advisories/github-reviewed/2022/05/GHSA-mm73-86f9-5x5c/GHSA-mm73-86f9-5x5c.json new file mode 100644 index 00000000000..745c2e55498 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-mm73-86f9-5x5c/GHSA-mm73-86f9-5x5c.json @@ -0,0 +1,99 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm73-86f9-5x5c", + "modified": "2024-04-23T23:37:58Z", + "published": "2022-05-24T17:40:31Z", + "aliases": [ + "CVE-2021-20184" + ], + "summary": "Moodle Grade information disclosure in grade's external fetch functions", + "details": "It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.8" + }, + { + "fixed": "3.8.7" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.9" + }, + { + "fixed": "3.9.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.10" + }, + { + "fixed": "3.10.1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20184" + }, + { + "type": "PACKAGE", + "url": "https://github.com/moodle/moodle" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=417167" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-354" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-23T23:37:58Z", + "nvd_published_at": "2021-01-28T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-q6vw-27c6-jv9c/GHSA-q6vw-27c6-jv9c.json b/advisories/github-reviewed/2022/05/GHSA-q6vw-27c6-jv9c/GHSA-q6vw-27c6-jv9c.json new file mode 100644 index 00000000000..9bdfde7fda9 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-q6vw-27c6-jv9c/GHSA-q6vw-27c6-jv9c.json @@ -0,0 +1,65 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6vw-27c6-jv9c", + "modified": "2024-04-23T23:39:18Z", + "published": "2022-05-24T22:28:53Z", + "aliases": [ + "CVE-2019-18210" + ], + "summary": "Moodle Persistent Cross-site Scripting (XSS)", + "details": "Persistent XSS in `/course/modedit.php` of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of another user (e.g., enrolled student or site administrator) via the introeditor[text] parameter. NOTE: the discoverer and vendor disagree on whether Moodle customers have a reasonable expectation that anyone authenticated as a Teacher can be trusted with the ability to add arbitrary JavaScript (this ability is not documented on Moodle's Teacher_role page). Because the vendor has this expectation, they have stated \"this report has been closed as a false positive, and not a bug.\"", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.7" + }, + { + "last_affected": "3.7.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-18210" + }, + { + "type": "WEB", + "url": "https://docs.moodle.org/38/en/Teacher_role" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Danbardo/4a6b0fe8cb21ec6d7c54e6ac951bdb0a" + }, + { + "type": "PACKAGE", + "url": "https://github.com/moodle/moodle" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-23T23:39:18Z", + "nvd_published_at": "2020-02-11T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/03/GHSA-4qxc-qxrp-33cw/GHSA-4qxc-qxrp-33cw.json b/advisories/unreviewed/2022/03/GHSA-4qxc-qxrp-33cw/GHSA-4qxc-qxrp-33cw.json deleted file mode 100644 index 4cc6185ad93..00000000000 --- a/advisories/unreviewed/2022/03/GHSA-4qxc-qxrp-33cw/GHSA-4qxc-qxrp-33cw.json +++ /dev/null @@ -1,39 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-4qxc-qxrp-33cw", - "modified": "2022-03-19T00:01:19Z", - "published": "2022-03-12T00:00:33Z", - "aliases": [ - "CVE-2021-32476" - ], - "details": "A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-32476" - }, - { - "type": "WEB", - "url": "https://moodle.org/mod/forum/discuss.php?d=422310" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-400", - "CWE-770" - ], - "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2022-03-11T18:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/03/GHSA-5wjh-v7c8-wrhx/GHSA-5wjh-v7c8-wrhx.json b/advisories/unreviewed/2022/03/GHSA-5wjh-v7c8-wrhx/GHSA-5wjh-v7c8-wrhx.json deleted file mode 100644 index 53a79f1a25d..00000000000 --- a/advisories/unreviewed/2022/03/GHSA-5wjh-v7c8-wrhx/GHSA-5wjh-v7c8-wrhx.json +++ /dev/null @@ -1,38 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-5wjh-v7c8-wrhx", - "modified": "2022-03-19T00:01:20Z", - "published": "2022-03-12T00:00:33Z", - "aliases": [ - "CVE-2021-32475" - ], - "details": "ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-32475" - }, - { - "type": "WEB", - "url": "https://moodle.org/mod/forum/discuss.php?d=422309" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2022-03-11T18:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/03/GHSA-rvmc-8gmg-ggqr/GHSA-rvmc-8gmg-ggqr.json b/advisories/unreviewed/2022/03/GHSA-rvmc-8gmg-ggqr/GHSA-rvmc-8gmg-ggqr.json deleted file mode 100644 index d746a116a8c..00000000000 --- a/advisories/unreviewed/2022/03/GHSA-rvmc-8gmg-ggqr/GHSA-rvmc-8gmg-ggqr.json +++ /dev/null @@ -1,38 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-rvmc-8gmg-ggqr", - "modified": "2022-03-19T00:01:20Z", - "published": "2022-03-12T00:00:32Z", - "aliases": [ - "CVE-2021-32474" - ], - "details": "An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required site administrator access or access to the keypair. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-32474" - }, - { - "type": "WEB", - "url": "https://moodle.org/mod/forum/discuss.php?d=422308" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-89" - ], - "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2022-03-11T18:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-4w4j-9533-82qg/GHSA-4w4j-9533-82qg.json b/advisories/unreviewed/2022/05/GHSA-4w4j-9533-82qg/GHSA-4w4j-9533-82qg.json deleted file mode 100644 index 582e47a66b2..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-4w4j-9533-82qg/GHSA-4w4j-9533-82qg.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-4w4j-9533-82qg", - "modified": "2022-05-24T17:35:32Z", - "published": "2022-05-24T17:35:32Z", - "aliases": [ - "CVE-2020-25631" - ], - "details": "A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScript in a book's chapter title, which was not escaped on the \"Add new chapter\" page. This is fixed in 3.9.2, 3.8.5 and 3.7.8.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25631" - }, - { - "type": "WEB", - "url": "https://moodle.org/mod/forum/discuss.php?d=410843" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2020-12-08T01:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-774q-wfcp-vc2q/GHSA-774q-wfcp-vc2q.json b/advisories/unreviewed/2022/05/GHSA-774q-wfcp-vc2q/GHSA-774q-wfcp-vc2q.json deleted file mode 100644 index bdd84eda8ab..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-774q-wfcp-vc2q/GHSA-774q-wfcp-vc2q.json +++ /dev/null @@ -1,39 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-774q-wfcp-vc2q", - "modified": "2022-05-24T17:11:48Z", - "published": "2022-05-24T17:11:48Z", - "aliases": [ - "CVE-2019-14883" - ], - "details": "A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their token.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-14883" - }, - { - "type": "WEB", - "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14883" - }, - { - "type": "WEB", - "url": "https://moodle.org/mod/forum/discuss.php?d=393586#p1586750" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2020-03-18T13:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-c3j6-33r4-89q3/GHSA-c3j6-33r4-89q3.json b/advisories/unreviewed/2022/05/GHSA-c3j6-33r4-89q3/GHSA-c3j6-33r4-89q3.json deleted file mode 100644 index 28005a8a1fd..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-c3j6-33r4-89q3/GHSA-c3j6-33r4-89q3.json +++ /dev/null @@ -1,39 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-c3j6-33r4-89q3", - "modified": "2022-10-22T12:00:27Z", - "published": "2022-05-24T17:40:31Z", - "aliases": [ - "CVE-2021-20185" - ], - "details": "It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which could result in client-side (browser) denial of service for users receiving very large messages.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20185" - }, - { - "type": "WEB", - "url": "https://moodle.org/mod/forum/discuss.php?d=417168" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-400", - "CWE-770" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2021-01-28T20:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-g39c-mccf-rxjv/GHSA-g39c-mccf-rxjv.json b/advisories/unreviewed/2022/05/GHSA-g39c-mccf-rxjv/GHSA-g39c-mccf-rxjv.json deleted file mode 100644 index 04bad0d879c..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-g39c-mccf-rxjv/GHSA-g39c-mccf-rxjv.json +++ /dev/null @@ -1,42 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-g39c-mccf-rxjv", - "modified": "2022-06-15T00:00:24Z", - "published": "2022-05-24T19:21:10Z", - "aliases": [ - "CVE-2021-43560" - ], - "details": "A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-43560" - }, - { - "type": "WEB", - "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2021519" - }, - { - "type": "WEB", - "url": "https://moodle.org/mod/forum/discuss.php?d=429100" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-668" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2021-11-22T16:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-grj4-g57c-9xmv/GHSA-grj4-g57c-9xmv.json b/advisories/unreviewed/2022/05/GHSA-grj4-g57c-9xmv/GHSA-grj4-g57c-9xmv.json deleted file mode 100644 index c169efe9b3d..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-grj4-g57c-9xmv/GHSA-grj4-g57c-9xmv.json +++ /dev/null @@ -1,47 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-grj4-g57c-9xmv", - "modified": "2022-05-24T17:44:37Z", - "published": "2022-05-24T17:44:37Z", - "aliases": [ - "CVE-2021-20282" - ], - "details": "When creating a user account, it was possible to verify the account without having access to the verification email link/secret in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20282" - }, - { - "type": "WEB", - "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1939046" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AFSNJ7XHVTC52RSRX2GBQFF3VEEAY2MS" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UFH5DDMU5TZ3JT4Q52WMRAHACA5MHIMT" - }, - { - "type": "WEB", - "url": "https://moodle.org/mod/forum/discuss.php?d=419653" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-863" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2021-03-15T22:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-h8m4-h385-qhqv/GHSA-h8m4-h385-qhqv.json b/advisories/unreviewed/2022/05/GHSA-h8m4-h385-qhqv/GHSA-h8m4-h385-qhqv.json deleted file mode 100644 index e995f128981..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-h8m4-h385-qhqv/GHSA-h8m4-h385-qhqv.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-h8m4-h385-qhqv", - "modified": "2022-05-24T17:40:31Z", - "published": "2022-05-24T17:40:31Z", - "aliases": [ - "CVE-2021-20186" - ], - "details": "It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20186" - }, - { - "type": "WEB", - "url": "https://moodle.org/mod/forum/discuss.php?d=417170" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2021-01-28T19:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-j8wr-7xxj-c2fr/GHSA-j8wr-7xxj-c2fr.json b/advisories/unreviewed/2022/05/GHSA-j8wr-7xxj-c2fr/GHSA-j8wr-7xxj-c2fr.json deleted file mode 100644 index 3f9593e921c..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-j8wr-7xxj-c2fr/GHSA-j8wr-7xxj-c2fr.json +++ /dev/null @@ -1,39 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-j8wr-7xxj-c2fr", - "modified": "2022-05-24T16:48:40Z", - "published": "2022-05-24T16:48:40Z", - "aliases": [ - "CVE-2019-10134" - ], - "details": "A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-10134" - }, - { - "type": "WEB", - "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10134" - }, - { - "type": "WEB", - "url": "https://moodle.org/mod/forum/discuss.php?d=386524" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2019-06-26T19:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-m98q-q59p-r9fv/GHSA-m98q-q59p-r9fv.json b/advisories/unreviewed/2022/05/GHSA-m98q-q59p-r9fv/GHSA-m98q-q59p-r9fv.json deleted file mode 100644 index 07476d3d75d..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-m98q-q59p-r9fv/GHSA-m98q-q59p-r9fv.json +++ /dev/null @@ -1,39 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-m98q-q59p-r9fv", - "modified": "2022-05-24T17:11:48Z", - "published": "2022-05-24T17:11:48Z", - "aliases": [ - "CVE-2019-14882" - ], - "details": "A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed in the Lesson edit page.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-14882" - }, - { - "type": "WEB", - "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14882" - }, - { - "type": "WEB", - "url": "https://moodle.org/mod/forum/discuss.php?d=393585#p1586747" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2020-03-18T13:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-mm73-86f9-5x5c/GHSA-mm73-86f9-5x5c.json b/advisories/unreviewed/2022/05/GHSA-mm73-86f9-5x5c/GHSA-mm73-86f9-5x5c.json deleted file mode 100644 index d865553072d..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-mm73-86f9-5x5c/GHSA-mm73-86f9-5x5c.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-mm73-86f9-5x5c", - "modified": "2022-05-24T17:40:31Z", - "published": "2022-05-24T17:40:31Z", - "aliases": [ - "CVE-2021-20184" - ], - "details": "It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20184" - }, - { - "type": "WEB", - "url": "https://moodle.org/mod/forum/discuss.php?d=417167" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-354" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2021-01-28T19:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-q6vw-27c6-jv9c/GHSA-q6vw-27c6-jv9c.json b/advisories/unreviewed/2022/05/GHSA-q6vw-27c6-jv9c/GHSA-q6vw-27c6-jv9c.json deleted file mode 100644 index 45cdba1d1b2..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-q6vw-27c6-jv9c/GHSA-q6vw-27c6-jv9c.json +++ /dev/null @@ -1,39 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-q6vw-27c6-jv9c", - "modified": "2022-05-24T22:28:53Z", - "published": "2022-05-24T22:28:53Z", - "aliases": [ - "CVE-2019-18210" - ], - "details": "** DISPUTED ** Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of another user (e.g., enrolled student or site administrator) via the introeditor[text] parameter. NOTE: the discoverer and vendor disagree on whether Moodle customers have a reasonable expectation that anyone authenticated as a Teacher can be trusted with the ability to add arbitrary JavaScript (this ability is not documented on Moodle's Teacher_role page). Because the vendor has this expectation, they have stated \"this report has been closed as a false positive, and not a bug.”", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-18210" - }, - { - "type": "WEB", - "url": "https://docs.moodle.org/38/en/Teacher_role" - }, - { - "type": "WEB", - "url": "https://gist.github.com/Danbardo/4a6b0fe8cb21ec6d7c54e6ac951bdb0a" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": "LOW", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2020-02-11T14:15:00Z" - } -} \ No newline at end of file