The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published: 2024-06-18T19:49:26.986Z

Updated: 2024-08-02T04:04:25.068Z

Reserved: 2024-06-12T14:08:44.047Z

Link: CVE-2024-38275

cve-icon Vulnrichment

Updated: 2024-07-02T13:43:48.130Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-18T20:15:13.970

Modified: 2024-07-03T02:04:53.613

Link: CVE-2024-38275

cve-icon Redhat

No data.