CVE Vulnerabilities

CVE-2024-38277

Use of a Key Past its Expiration Date

Published: Jun 18, 2024 | Modified: Aug 07, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A unique key should be generated for a users QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.

Weakness

The product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.

Affected Software

NameVendorStart VersionEnd Version
MoodleMoodle4.1.0 (including)4.1.11 (excluding)
MoodleMoodle4.2.0 (including)4.2.8 (excluding)
MoodleMoodle4.3.0 (including)4.3.5 (excluding)
MoodleMoodle4.4.0 (including)4.4.0 (including)
MoodleUbuntuupstream*

Potential Mitigations

References