A flaw was found in moodle. When creating an export of site administration presets, some sensitive secrets and keys are not being excluded from the export, which could result in them unintentionally being leaked if the presets are shared with a third party.
History

Tue, 12 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-922
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 11 Nov 2024 12:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in moodle. When creating an export of site administration presets, some sensitive secrets and keys are not being excluded from the export, which could result in them unintentionally being leaked if the presets are shared with a third party.
Title Moodle: admin presets export tool includes some secrets that should not be exported
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published: 2024-11-11T12:14:22.984Z

Updated: 2024-11-12T15:03:14.383Z

Reserved: 2024-08-13T07:15:00.597Z

Link: CVE-2024-43427

cve-icon Vulnrichment

Updated: 2024-11-12T15:03:08.164Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-11T13:15:03.530

Modified: 2024-11-12T15:35:06.950

Link: CVE-2024-43427

cve-icon Redhat

No data.