Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j8wr-7xxj-c2fr

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.2

Описание

Moodle Private files uploaded via incoming mail processing could bypass quota restrictions

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.6, < 3.6.4

3.6.4

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.5, < 3.5.6

3.5.6

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.4, < 3.4.9

3.4.9

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.1, < 3.1.18

3.1.18

EPSS

Процентиль: 40%
0.00179
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 3.7
ubuntu
почти 6 лет назад

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.

CVSS3: 3.7
nvd
почти 6 лет назад

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.

CVSS3: 3.7
debian
почти 6 лет назад

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. ...

EPSS

Процентиль: 40%
0.00179
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-20