CVE-2021-20283
Summary
| CVE | CVE-2021-20283 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-15 22:15:00 UTC |
| Updated | 2023-11-07 03:29:00 UTC |
| Description | The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 34 Update: moodle-3.10.2-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| 1939051 – (CVE-2021-20283) CVE-2021-20283 moodle: Fetching a user's enrolled courses via web services did not check profile access in each course |
MISC |
bugzilla.redhat.com |
|
| [SECURITY] Fedora 34 Update: moodle-3.10.2-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Moodle.org: MSA-21-0010: Fetching a user's enrolled courses via web services did not check profile access in each course |
MISC |
moodle.org |
|
| [SECURITY] Fedora 32 Update: moodle-3.8.8-1.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 32 Update: moodle-3.8.8-1.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 281474 Fedora Security Update for moodle (FEDORA-2021-50f63a0161)
- 281475 Fedora Security Update for moodle (FEDORA-2021-1c27e89d49)
- 281476 Fedora Security Update for moodle (FEDORA-2021-431b232659)