GHSA-cc94-hwj3-rf65

Suggest an improvement
Source
https://github.com/advisories/GHSA-cc94-hwj3-rf65
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-cc94-hwj3-rf65/GHSA-cc94-hwj3-rf65.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-cc94-hwj3-rf65
Aliases
  • CVE-2013-1835
Published
2022-05-13T01:12:59Z
Modified
2024-12-06T05:38:11Z
Summary
Moodle's login_as feature leaks information from external repositories
Details

Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote authenticated administrators to obtain sensitive information from the external repositories of arbitrary users by leveraging the login_as feature.

Database specific
{
    "cwe_ids": [
        "CWE-200"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2024-01-23T14:37:24Z",
    "nvd_published_at": "2013-03-25T21:55:00Z",
    "severity": "LOW"
}
References

Affected packages

Packagist / moodle/moodle

Package

Name
moodle/moodle
Purl
pkg:composer/moodle/moodle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.2.8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-cc94-hwj3-rf65/GHSA-cc94-hwj3-rf65.json"

Packagist / moodle/moodle

Package

Name
moodle/moodle
Purl
pkg:composer/moodle/moodle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.3.0
Fixed
2.3.5

Affected versions

v2.*
v2.3.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-cc94-hwj3-rf65/GHSA-cc94-hwj3-rf65.json"

Packagist / moodle/moodle

Package

Name
moodle/moodle
Purl
pkg:composer/moodle/moodle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.4.0
Fixed
2.4.2

Affected versions

v2.*
v2.4.0
v2.4.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-cc94-hwj3-rf65/GHSA-cc94-hwj3-rf65.json"