CVE Vulnerabilities

CVE-2024-38277

Use of a Key Past its Expiration Date

Published: Jun 18, 2024 | Modified: Dec 04, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

A unique key should be generated for a users QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.

Weakness

The product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.

Affected Software

Name Vendor Start Version End Version
Moodle Ubuntu upstream *

Potential Mitigations

References