CVE-2024-38275

HIGH7.5EPSS 0.55%

Moodle HTTP authorization header is preserved between "emulated redirects"

發布日:2024/6/18修改日:2025/5/1
也稱為:GHSA-p2cj-86v4-7782BIT-moodle-2024-38275

描述

The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

參考連結(7)