CVE Vulnerabilities

CVE-2021-36395

Uncontrolled Recursion

Published: Mar 06, 2023 | Modified: Mar 13, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In Moodle, the file repositorys URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.

Weakness

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Affected Software

Name Vendor Start Version End Version
Moodle Moodle * 3.9.8 (excluding)
Moodle Moodle 3.10.0 (including) 3.10.5 (excluding)
Moodle Moodle 3.11.0 (including) 3.11.1 (excluding)

Potential Mitigations

References