CVE-2014-0008
Summary
| CVE | CVE-2014-0008 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-01-20 15:14:25 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | lib/adminlib.php in Moodle through 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 logs cleartext passwords, which allows remote authenticated administrators to obtain sensitive information by reading the Config Changes Report. |
Risk And Classification
Primary CVSS: v2.0 4 from [email protected]
AV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS: 0.004230000 probability, percentile 0.621330000 (date 2026-05-03)
Problem Types: CWE-255 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:S/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Moodle | Moodle | 2.3.0 | All | All | All |
| Application | Moodle | Moodle | 2.3.1 | All | All | All |
| Application | Moodle | Moodle | 2.3.10 | All | All | All |
| Application | Moodle | Moodle | 2.3.2 | All | All | All |
| Application | Moodle | Moodle | 2.3.3 | All | All | All |
| Application | Moodle | Moodle | 2.3.4 | All | All | All |
| Application | Moodle | Moodle | 2.3.5 | All | All | All |
| Application | Moodle | Moodle | 2.3.6 | All | All | All |
| Application | Moodle | Moodle | 2.3.7 | All | All | All |
| Application | Moodle | Moodle | 2.3.8 | All | All | All |
| Application | Moodle | Moodle | 2.3.9 | All | All | All |
| Application | Moodle | Moodle | 2.4.0 | All | All | All |
| Application | Moodle | Moodle | 2.4.1 | All | All | All |
| Application | Moodle | Moodle | 2.4.2 | All | All | All |
| Application | Moodle | Moodle | 2.4.3 | All | All | All |
| Application | Moodle | Moodle | 2.4.4 | All | All | All |
| Application | Moodle | Moodle | 2.4.5 | All | All | All |
| Application | Moodle | Moodle | 2.4.6 | All | All | All |
| Application | Moodle | Moodle | 2.4.7 | All | All | All |
| Application | Moodle | Moodle | 2.5.0 | All | All | All |
| Application | Moodle | Moodle | 2.5.1 | All | All | All |
| Application | Moodle | Moodle | 2.5.2 | All | All | All |
| Application | Moodle | Moodle | 2.5.3 | All | All | All |
| Application | Moodle | Moodle | 2.6.0 | All | All | All |
| Application | Moodle | Moodle | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 20 Update: moodle-2.5.4-1.fc20 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Official Moodle git projects - moodle.git/search | af854a3a-2127-422b-91ae-364da2661108 | git.moodle.org | Patch |
| oss-security - Moodle security notifications public | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| Moodle Discloses Some Passwords to Remote Authenticated Users - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Moodle.org: MSA-14-0001: Config passwords visibility issue | af854a3a-2127-422b-91ae-364da2661108 | moodle.org | Patch, Vendor Advisory |
| [SECURITY] Fedora 19 Update: moodle-2.4.8-1.fc19 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.