Описание
Moodle does not consider "don't send" attributes during hub registration
Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not consider "don't send" attributes during hub registration, which allows remote hubs to obtain sensitive site information by reading form data.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2013-2081
- https://github.com/moodle/moodle/commit/1d79b726d762bcc629c1a2a74cfa3eca5a7c5da7
- https://github.com/moodle/moodle/commit/1fc34e37fdc57b4ec303cb942dc5d5535b953ed7
- https://github.com/moodle/moodle/commit/4d65904bc132548a2ef4c2a40bf5ba2cffb5f68f
- https://github.com/moodle/moodle/commit/54a3ce69e9ca751fffd0b3e0eb5be4add50de113
- https://github.com/moodle/moodle/commit/60c468bcb3b6f867a70f2f30427b52e0362e93d1
- https://github.com/moodle/moodle/commit/667eaec4d2679a8bc1fcd9f0ff17a1be2babccb0
- https://github.com/moodle/moodle/commit/669dee58048b18d9034a7b2367b97a50b498b0e0
- https://github.com/moodle/moodle/commit/a811e8ac56e49a174b68ceade81197c80be4b325
- https://github.com/moodle/moodle/commit/be6281e2cbc2fb40b96a48c07c80883fa80cd1b7
- https://github.com/moodle/moodle/commit/fd469033fa2c860647e48f3d543346503a37faa0
- https://moodle.org/mod/forum/discuss.php?d=228933
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37822
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106965.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106988.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/107026.html
- http://openwall.com/lists/oss-security/2013/05/21/1
Пакеты
moodle/moodle
< 2.2.10
2.2.10
moodle/moodle
>= 2.3.0, < 2.3.7
2.3.7
moodle/moodle
>= 2.4.0, < 2.4.4
2.4.4
Связанные уязвимости
Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not consider "don't send" attributes during hub registration, which allows remote hubs to obtain sensitive site information by reading form data.
Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not consider "don't send" attributes during hub registration, which allows remote hubs to obtain sensitive site information by reading form data.
Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2. ...