Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c7v4-m269-4995

Опубликовано: 21 окт. 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Exposure of Sensitive Information to an Unauthorized Actor in Moodle

The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.9.0, < 3.9.3

3.9.3

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.8.0, < 3.8.6

3.8.6

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.7.0, < 3.7.9

3.7.9

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.10.0-beta, < 3.10.0

3.10.0

EPSS

Процентиль: 54%
0.00313
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 4 лет назад

The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.

CVSS3: 5.3
nvd
больше 4 лет назад

The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.

CVSS3: 5.3
debian
больше 4 лет назад

The participants table download in Moodle always included user emails, ...

EPSS

Процентиль: 54%
0.00313
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200