CVE Vulnerabilities

CVE-2018-10889

Insertion of Sensitive Information into Log File

Published: Jul 10, 2018 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Moodle Moodle 3.3.0 (including) 3.3.7 (excluding)
Moodle Moodle 3.4.0 (including) 3.4.4 (excluding)
Moodle Moodle 3.5.0 (including) 3.5.1 (excluding)
Moodle Ubuntu artful *
Moodle Ubuntu bionic *
Moodle Ubuntu cosmic *
Moodle Ubuntu disco *
Moodle Ubuntu eoan *
Moodle Ubuntu trusty *
Moodle Ubuntu xenial *

Potential Mitigations

References