Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-66xp-28cq-mrf2

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Moodle Denial of Service

A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk. This affects versions 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.9, < 3.9.2

3.9.2

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.8, < 3.8.5

3.8.5

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.7, < 3.7.8

3.7.8

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.5, < 3.5.14

3.5.14

EPSS

Процентиль: 65%
0.00497
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk. This affects versions 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 7.5
nvd
больше 4 лет назад

A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk. This affects versions 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 7.5
debian
больше 4 лет назад

A vulnerability was found in Moodle where the decompressed size of zip ...

EPSS

Процентиль: 65%
0.00497
Низкий

7.5 High

CVSS3

Дефекты

CWE-400