GHSA-cc94-hwj3-rf65

Suggest an improvement
Source
https://github.com/advisories/GHSA-cc94-hwj3-rf65
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-cc94-hwj3-rf65/GHSA-cc94-hwj3-rf65.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-cc94-hwj3-rf65
Aliases
  • CVE-2013-1835
Published
2022-05-13T01:12:59Z
Modified
2024-12-06T05:38:11.994975Z
Summary
Moodle's login_as feature leaks information from external repositories
Details

Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote authenticated administrators to obtain sensitive information from the external repositories of arbitrary users by leveraging the login_as feature.

Database specific
{
    "nvd_published_at": "2013-03-25T21:55:00Z",
    "cwe_ids": [
        "CWE-200"
    ],
    "severity": "LOW",
    "github_reviewed": true,
    "github_reviewed_at": "2024-01-23T14:37:24Z"
}
References

Affected packages

Packagist / moodle/moodle

Package

Name
moodle/moodle
Purl
pkg:composer/moodle/moodle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.2.8

Packagist / moodle/moodle

Package

Name
moodle/moodle
Purl
pkg:composer/moodle/moodle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.3.0
Fixed
2.3.5

Affected versions

v2.*

v2.3.4

Packagist / moodle/moodle

Package

Name
moodle/moodle
Purl
pkg:composer/moodle/moodle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.4.0
Fixed
2.4.2

Affected versions

v2.*

v2.4.0
v2.4.1