CVE-2021-20283
Description
The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
CWE
- CWE-863 — CWE-863
Affected
- n/a / moodle — v=Fixed in 3.10.2, 3.9.5, 3.8.8, 3.5.17 [affected]
CVSS
- (none)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1939051 x_refsource_MISC
- https://moodle.org/mod/forum/discuss.php?d=419654 x_refsource_MISC
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AFSNJ7XHVTC52RSRX2GBQFF3VEEAY2MS/ vendor-advisory, x_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UFH5DDMU5TZ3JT4Q52WMRAHACA5MHIMT/ vendor-advisory, x_refsource_FEDORA
Source
cvelistV5-main/cves/2021/20xxx/CVE-2021-20283.json