MSA-21-0035: Arbitrary file read by site administrators via LaTeX preamble

by Michael Hawkins.  

Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account.


...
Severity/Risk:Serious
Versions affected:3.11 to 3.11.2, 3.10 to 3.10.6, 3.9 to 3.9.9 and earlier unsupported versions
Versions fixed:3.11.3, 3.10.7 and 3.9.10
Reported by:raisin_bugbou
Leer más...

MSA-21-0034: Authentication bypass risk when using external database authentication

by Michael Hawkins.  

An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.


...
Severity/Risk:Serious
Versions affected:3.11 to 3.11.2, 3.10 to 3.10.6, 3.9 to 3.9.9 and earlier unsupported versions
Versions fixed:3.11.3, 3.10.7 and 3.9.10
Reported by:adeadead
CVE
Leer más...

MSA-21-0033: Course participants download did not restrict which users could be exported

by Michael Hawkins.  

Insufficient capability checks made it possible for teachers to download users outside of their courses.


...
Severity/Risk:Minor
Versions affected:3.11 to 3.11.2, 3.10 to 3.10.6, 3.9 to 3.9.9 and earlier unsupported versions
Versions fixed:3.11.3, 3.10.7 and 3.9.10
Reported by:Paul Holden
CVE identifier:CVE-2021-40692
Changes
Leer más...

MSA-21-0032: Session Hijack risk when Shibboleth authentication is enabled

by Michael Hawkins.  

A session hijack risk was identified in the Shibboleth authentication plugin. (Note: Shibboleth authentication is disabled by default in Moodle.)


...
Severity/Risk:Serious
Versions affected:3.11 to 3.11.2, 3.10 to 3.10.6, 3.9 to 3.9.9 and earlier unsupported versions
Versions fixed:3.11.3, 3.10.7 and 3.9.10
Reported by:Robin
Leer más...