Описание
Moodle HTTP authorization header is preserved between "emulated redirects"
The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2024-38275
- https://github.com/moodle/moodle/commit/0df3c5837a592e6663c4d531ff6a1f776bc2f785
- https://github.com/moodle/moodle/commit/3e38c84315a7991ce5ef5f241f5e873b5ca24f01
- https://github.com/moodle/moodle/commit/836b2c23a210317d130017d77bb64e3b510869a9
- https://github.com/moodle/moodle/commit/f7988538b2208c55f2c40ce4f0815901dc88049b
- https://moodle.org/mod/forum/discuss.php?d=459500
Пакеты
moodle/moodle
>= 4.4.0-beta, < 4.4.1
4.4.1
moodle/moodle
>= 4.3.0-beta, < 4.3.5
4.3.5
moodle/moodle
>= 4.2.0-beta, < 4.2.8
4.2.8
moodle/moodle
< 4.1.11
4.1.11
EPSS
5.3 Medium
CVSS4
7.5 High
CVSS3
CVE ID
Дефекты
Связанные уязвимости
The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
The cURL wrapper in Moodle retained the original request headers when ...
EPSS
5.3 Medium
CVSS4
7.5 High
CVSS3