CVE Vulnerabilities

CVE-2018-10889

Insertion of Sensitive Information into Log File

Published: Jul 10, 2018 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
MoodleMoodle3.3.0 (including)3.3.7 (excluding)
MoodleMoodle3.4.0 (including)3.4.4 (excluding)
MoodleMoodle3.5.0 (including)3.5.1 (excluding)
MoodleUbuntuartful*
MoodleUbuntubionic*
MoodleUbuntucosmic*
MoodleUbuntudisco*
MoodleUbuntueoan*
MoodleUbuntutrusty*
MoodleUbuntuxenial*

Potential Mitigations

References