GHSA-5282-96ff-xx3h

Suggest an improvement
Source
https://github.com/advisories/GHSA-5282-96ff-xx3h
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5282-96ff-xx3h/GHSA-5282-96ff-xx3h.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5282-96ff-xx3h
Aliases
Published
2022-05-13T01:12:38Z
Modified
2024-02-16T08:22:04.622190Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Moodle sensitive information disclosure
Details

The capability check to access other badges in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to read the badges of other users.

Database specific
{
    "nvd_published_at": "2017-04-20T21:59:00Z",
    "cwe_ids": [
        "CWE-200"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2023-07-28T22:01:33Z"
}
References

Affected packages

Packagist / moodle/moodle

Package

Name
moodle/moodle
Purl
pkg:composer/moodle/moodle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.0.0
Fixed
3.0.4

Affected versions

v3.*

v3.0.0
v3.0.1
v3.0.2
v3.0.3

Database specific

{
    "last_known_affected_version_range": "<= 3.0.3"
}

Packagist / moodle/moodle

Package

Name
moodle/moodle
Purl
pkg:composer/moodle/moodle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.9.0
Fixed
2.9.6

Affected versions

v2.*

v2.9.0
v2.9.1
v2.9.2
v2.9.3
v2.9.4
v2.9.5

Database specific

{
    "last_known_affected_version_range": "<= 2.9.5"
}

Packagist / moodle/moodle

Package

Name
moodle/moodle
Purl
pkg:composer/moodle/moodle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.8.0
Fixed
2.8.12

Affected versions

v2.*

v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.5
v2.8.6
v2.8.7
v2.8.8
v2.8.9
v2.8.10
v2.8.11

Database specific

{
    "last_known_affected_version_range": "<= 2.8.11"
}

Packagist / moodle/moodle

Package

Name
moodle/moodle
Purl
pkg:composer/moodle/moodle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.7.0
Fixed
2.7.14

Affected versions

v2.*

v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.7.6
v2.7.7
v2.7.8
v2.7.9
v2.7.10
v2.7.11
v2.7.12
v2.7.13

Database specific

{
    "last_known_affected_version_range": "<= 2.7.13"
}