CVE-2020-9387
Summary
| CVE | CVE-2020-9387 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-30 13:15:00 UTC |
| Updated | 2020-05-12 16:03:00 UTC |
| Description | In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' is turned on. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mahara | Mahara | All | All | All | All |
| Application | Mahara | Mahara | 20.04 | rc1 | All | All |
| Application | Mahara | Mahara | 20.04 | rc2 | All | All |
| Application | Mahara | Mahara | All | All | All | All |
| Application | Mahara | Mahara | 20.04 | rc1 | All | All |
| Application | Mahara | Mahara | 20.04 | rc2 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug #1836984 “Elasticsearch not restricting the user search when...” : Bugs : Mahara | CONFIRM | bugs.launchpad.net | Issue Tracking, Patch, Third Party Advisory |
| Security Announcements - Security issue relating to the Elasticsearch results and Isolated institutions <18.10.6, <19.04.5, <19.10.3 - Mahara ePortfolio System | CONFIRM | mahara.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.