CVE Vulnerabilities

CVE-2024-43432

Cleartext Transmission of Sensitive Information

Published: Nov 11, 2024 | Modified: May 01, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Moodle Moodle * 4.1.12 (excluding)
Moodle Moodle 4.2.0 (including) 4.2.9 (excluding)
Moodle Moodle 4.3.0 (including) 4.3.6 (excluding)
Moodle Moodle 4.4.0 (including) 4.4.2 (excluding)

Potential Mitigations

References