CVE Vulnerabilities

CVE-2019-9708

Published: May 07, 2019 | Modified: Aug 24, 2020
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. A site administrator can suspend the system user (root), causing all users to be locked out from the system.

Affected Software

Name Vendor Start Version End Version
Mahara Mahara 17.10.0 (including) 17.10.8 (excluding)
Mahara Mahara 18.04.0 (including) 18.04.4 (excluding)
Mahara Mahara 18.10.0 (including) 18.10.1 (excluding)

References