In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Moodle | Moodle | * | 3.9.8 (excluding) |
Moodle | Moodle | 3.10.0 (including) | 3.10.5 (excluding) |
Moodle | Moodle | 3.11.0 (including) | 3.11.1 (excluding) |
Moodle | Ubuntu | bionic | * |
Moodle | Ubuntu | trusty | * |
Moodle | Ubuntu | xenial | * |
Such a scenario is commonly observed when: