Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-38275

Опубликовано: 18 июн. 2024
Источник: debian

Описание

The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
moodleremovedpackage

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 лет назад

The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

CVSS3: 7.5
nvd
около 2 лет назад

The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

CVSS3: 7.5
github
около 2 лет назад

Moodle HTTP authorization header is preserved between "emulated redirects"

CVSS3: 7.4
redos
около 2 лет назад

Множественные уязвимости moodle