HIGH
In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course
Published Nov 19, 2020
7.5
HIGHCVSS 3.1
EPSS 1.61%
Description
In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.
Affected products
- Vendor n/a Product Moodle Defaultn/a
- Version Fixed in 3.10StatusaffectedConstraints-
- Version Fixed in 3.5.15StatusaffectedConstraints-
- Version Fixed in 3.7.9StatusaffectedConstraints-
- Version Fixed in 3.8.6StatusaffectedConstraints-
- Version Fixed in 3.9.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| n/a | Moodle | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- https://bugzilla.redhat.com/show_bug.cgi?id=1895425 Issue TrackingThird Party Advisory
- https://github.com/advisories/GHSA-h77r-rp97-7rv4 Advisory
- https://github.com/moodle/moodle/commit/b8e1eec4c77c858de87fedf4e405e929539ea0c5
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4NNFCHPPHRJNJROIX6SYMHOC6HMKP3GU/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B55KXBVAT45MDASJ3EK6VIGQOYGJ4NH6/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4NNFCHPPHRJNJROIX6SYMHOC6HMKP3GU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B55KXBVAT45MDASJ3EK6VIGQOYGJ4NH6/
- https://moodle.org/mod/forum/discuss.php?d=413936 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-25699
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 19, 2020
Updated Aug 4, 2024
Reserved Sep 16, 2020
Link CVE-2020-25699
CISA Vulnrichment
GHSA-H77R-RP97-7RV4 Updated n/a