Description
The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p2cj-86v4-7782 | Moodle HTTP authorization header is preserved between "emulated redirects" |
References
| Link | Providers |
|---|---|
| https://moodle.org/mod/forum/discuss.php?d=459500 |
|
History
Thu, 01 May 2025 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-459 | |
| CPEs | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2024-08-02T04:04:25.068Z
Reserved: 2024-06-12T14:08:44.047Z
Link: CVE-2024-38275
Updated: 2024-07-02T13:43:48.130Z
Status : Analyzed
Published: 2024-06-18T20:15:13.970
Modified: 2025-04-30T23:35:59.790
Link: CVE-2024-38275
No data.
OpenCVE Enrichment
No data.
Github GHSA