CVE Vulnerabilities

CVE-2023-5548

Acceptance of Extraneous Untrusted Data With Trusted Data

Published: Nov 09, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.

Weakness

The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.

Affected Software

Name Vendor Start Version End Version
Moodle Moodle * 3.9.24 (excluding)
Moodle Moodle 3.11.0 (including) 3.11.17 (excluding)
Moodle Moodle 4.0.0 (including) 4.0.11 (excluding)
Moodle Moodle 4.1.0 (including) 4.1.6 (excluding)
Moodle Moodle 4.2.0 (including) 4.2.3 (excluding)
Moodle Ubuntu bionic *
Moodle Ubuntu trusty *
Moodle Ubuntu xenial *

References