Описание
A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| moodle | removed | package |
EPSS
Процентиль: 16%
0.00243
Низкий
Связанные уязвимости
CVSS3: 5.4
ubuntu
около 2 лет назад
A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.
CVSS3: 5.4
nvd
около 2 лет назад
A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.
CVSS3: 6.5
github
около 2 лет назад
Moodle uses the same key for QR login and auto-login
CVSS3: 5.4
fstec
около 2 лет назад
Уязвимость виртуальной обучающей среды Moodle, связанная с использованием ключа после истечения срока его действия, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
EPSS
Процентиль: 16%
0.00243
Низкий