Описание
Moodle allowed some users without permission to view other users' full names
It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-20281
- https://github.com/moodle/moodle/commit/33d6017287e1835513a3de8edd3fbf7a6a90af9c
- https://bugzilla.redhat.com/show_bug.cgi?id=1939041
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AFSNJ7XHVTC52RSRX2GBQFF3VEEAY2MS
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UFH5DDMU5TZ3JT4Q52WMRAHACA5MHIMT
- https://moodle.org/mod/forum/discuss.php?d=419652
Пакеты
moodle/moodle
>= 3.10.0, < 3.10.2
3.10.2
moodle/moodle
>= 3.9.0, < 3.9.5
3.9.5
moodle/moodle
>= 3.8.0, < 3.8.8
3.8.8
moodle/moodle
>= 3.5, < 3.5.17
3.5.17
Связанные уязвимости
It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
It was possible for some users without permission to view other users' ...