The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://moodle.org/mod/forum/discuss.php?d=459500 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: fedora
Published: 2024-06-18T19:49:26.986Z
Updated: 2024-08-02T04:04:25.068Z
Reserved: 2024-06-12T14:08:44.047Z
Link: CVE-2024-38275
Vulnrichment
Updated: 2024-07-02T13:43:48.130Z
NVD
Status : Awaiting Analysis
Published: 2024-06-18T20:15:13.970
Modified: 2024-11-21T09:25:14.183
Link: CVE-2024-38275
Redhat
No data.