{"api_version":"1","generated_at":"2026-07-24T17:44:16+00:00","cve":"CVE-2021-20283","urls":{"html":"https://cve.report/CVE-2021-20283","api":"https://cve.report/api/cve/CVE-2021-20283.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-20283","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-20283"},"summary":{"title":"CVE-2021-20283","description":"The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2021-03-15 22:15:00","updated_at":"2023-11-07 03:29:00"},"problem_types":["CWE-862"],"metrics":[],"references":[{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AFSNJ7XHVTC52RSRX2GBQFF3VEEAY2MS/","name":"FEDORA-2021-1c27e89d49","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 34 Update: moodle-3.10.2-1.fc34 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1939051","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1939051","refsource":"MISC","tags":[],"title":"1939051 – (CVE-2021-20283) CVE-2021-20283 moodle: Fetching a user's enrolled courses via web services did not check profile access in each course","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AFSNJ7XHVTC52RSRX2GBQFF3VEEAY2MS/","name":"FEDORA-2021-1c27e89d49","refsource":"","tags":[],"title":"[SECURITY] Fedora 34 Update: moodle-3.10.2-1.fc34 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://moodle.org/mod/forum/discuss.php?d=419654","name":"https://moodle.org/mod/forum/discuss.php?d=419654","refsource":"MISC","tags":[],"title":"Moodle.org: MSA-21-0010: Fetching a user's enrolled courses via web services did not check profile access in each course","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UFH5DDMU5TZ3JT4Q52WMRAHACA5MHIMT/","name":"FEDORA-2021-50f63a0161","refsource":"","tags":[],"title":"[SECURITY] Fedora 32 Update: moodle-3.8.8-1.fc32 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UFH5DDMU5TZ3JT4Q52WMRAHACA5MHIMT/","name":"FEDORA-2021-50f63a0161","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 32 Update: moodle-3.8.8-1.fc32 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-20283","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-20283","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"20283","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"32","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"20283","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"34","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"20283","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"moodle","cpe5":"moodle","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-20283","qid":"281474","title":"Fedora Security Update for moodle (FEDORA-2021-50f63a0161)"},{"cve":"CVE-2021-20283","qid":"281475","title":"Fedora Security Update for moodle (FEDORA-2021-1c27e89d49)"},{"cve":"CVE-2021-20283","qid":"281476","title":"Fedora Security Update for moodle (FEDORA-2021-431b232659)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2021-20283","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"moodle","version":{"version_data":[{"version_value":"Fixed in 3.10.2, 3.9.5, 3.8.8, 3.5.17"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-863"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1939051","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1939051"},{"refsource":"MISC","name":"https://moodle.org/mod/forum/discuss.php?d=419654","url":"https://moodle.org/mod/forum/discuss.php?d=419654"},{"refsource":"FEDORA","name":"FEDORA-2021-1c27e89d49","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AFSNJ7XHVTC52RSRX2GBQFF3VEEAY2MS/"},{"refsource":"FEDORA","name":"FEDORA-2021-50f63a0161","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UFH5DDMU5TZ3JT4Q52WMRAHACA5MHIMT/"}]},"description":{"description_data":[{"lang":"eng","value":"The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17."}]}},"nvd":{"publishedDate":"2021-03-15 22:15:00","lastModifiedDate":"2023-11-07 03:29:00","problem_types":["CWE-862"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9.0","versionEndExcluding":"3.9.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5.0","versionEndExcluding":"3.5.17","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*","versionStartIncluding":"3.10.0","versionEndExcluding":"3.10.2","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8.0","versionEndExcluding":"3.8.8","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"20283","Ordinal":"194324","Title":"CVE-2021-20283","CVE":"CVE-2021-20283","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"20283","Ordinal":"1","NoteData":"The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"20283","Ordinal":"2","NoteData":"2021-03-15","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"20283","Ordinal":"3","NoteData":"2021-03-22","Type":"Other","Title":"Modified"}]}}}