UBUNTU-CVE-2021-20283

Source
https://ubuntu.com/security/CVE-2021-20283
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-20283.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2021-20283
Upstream
Published
2021-03-15T22:15:00Z
Modified
2025-10-24T04:50:05Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
  • Ubuntu - low
Summary
[none]
Details

The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

References

Affected packages

Ubuntu:16.04:LTS / moodle

Package

Name
moodle
Purl
pkg:deb/ubuntu/moodle@3.0.3+dfsg-0ubuntu1?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.7.9+dfsg-1
2.7.10+dfsg-1
2.7.11+dfsg-1
2.7.11+dfsg-2
2.7.12+dfsg-1
3.*
3.0.3+dfsg-0ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "moodle",
            "binary_version": "3.0.3+dfsg-0ubuntu1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-20283.json"

Ubuntu:18.04:LTS / moodle

Package

Name
moodle
Purl
pkg:deb/ubuntu/moodle@3.0.3+dfsg-0ubuntu1?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.0.3+dfsg-0ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "moodle",
            "binary_version": "3.0.3+dfsg-0ubuntu1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-20283.json"