CVE Vulnerabilities

CVE-2023-5548

Acceptance of Extraneous Untrusted Data With Trusted Data

Published: Nov 09, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.

Weakness

The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.

Affected Software

NameVendorStart VersionEnd Version
MoodleMoodle*3.9.24 (excluding)
MoodleMoodle3.11.0 (including)3.11.17 (excluding)
MoodleMoodle4.0.0 (including)4.0.11 (excluding)
MoodleMoodle4.1.0 (including)4.1.6 (excluding)
MoodleMoodle4.2.0 (including)4.2.3 (excluding)
MoodleUbuntubionic*
MoodleUbuntutrusty*
MoodleUbuntuxenial*

References