Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Moodle | Moodle | * | 3.9.24 (excluding) |
Moodle | Moodle | 3.11.0 (including) | 3.11.17 (excluding) |
Moodle | Moodle | 4.0.0 (including) | 4.0.11 (excluding) |
Moodle | Moodle | 4.1.0 (including) | 4.1.6 (excluding) |
Moodle | Moodle | 4.2.0 (including) | 4.2.3 (excluding) |
Moodle | Ubuntu | bionic | * |
Moodle | Ubuntu | trusty | * |
Moodle | Ubuntu | xenial | * |