calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an activity is hidden, which allows remote authenticated users to obtain sensitive information via a web-service request.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "2.6.11"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.0"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.3"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.4"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.5"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.6"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.7"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.8"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.9"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.10"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.11"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.12"
},
{
"introduced": "0"
},
{
"last_affected": "2.8.0"
},
{
"introduced": "0"
},
{
"last_affected": "2.8.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.8.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.8.3"
},
{
"introduced": "0"
},
{
"last_affected": "2.8.4"
},
{
"introduced": "0"
},
{
"last_affected": "2.8.5"
},
{
"introduced": "0"
},
{
"last_affected": "2.8.6"
},
{
"introduced": "0"
},
{
"last_affected": "2.8.7"
},
{
"introduced": "0"
},
{
"last_affected": "2.8.8"
},
{
"introduced": "0"
},
{
"last_affected": "2.8.9"
},
{
"introduced": "0"
},
{
"last_affected": "2.8.10"
},
{
"introduced": "0"
},
{
"last_affected": "2.9.0"
},
{
"introduced": "0"
},
{
"last_affected": "2.9.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.9.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.9.3"
},
{
"introduced": "0"
},
{
"last_affected": "2.9.4"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.0"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.1"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.2"
}
]
}