A unique key should be generated for a users QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.
The product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Moodle | Moodle | 4.1.0 (including) | 4.1.11 (excluding) |
Moodle | Moodle | 4.2.0 (including) | 4.2.8 (excluding) |
Moodle | Moodle | 4.3.0 (including) | 4.3.5 (excluding) |
Moodle | Moodle | 4.4.0 (including) | 4.4.0 (including) |
Moodle | Ubuntu | upstream | * |