Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vm9c-39jx-q45w

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

Moodle vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send "Cache-Control: private" HTTP headers, which allows remote attackers to obtain sensitive information by requesting a file that had been previously retrieved by a caching proxy server.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

< 2.3.10

2.3.10

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 2.4.0-beta, < 2.4.7

2.4.7

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 2.5.0-beta, < 2.5.3

2.5.3

EPSS

Процентиль: 51%
0.00283
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-200

Связанные уязвимости

ubuntu
больше 11 лет назад

lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send "Cache-Control: private" HTTP headers, which allows remote attackers to obtain sensitive information by requesting a file that had been previously retrieved by a caching proxy server.

nvd
больше 11 лет назад

lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send "Cache-Control: private" HTTP headers, which allows remote attackers to obtain sensitive information by requesting a file that had been previously retrieved by a caching proxy server.

debian
больше 11 лет назад

lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x b ...

EPSS

Процентиль: 51%
0.00283
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-200