CVE-2024-43426
Moodle: arbitrary file read risk through pdftex
7.5
HIGH
CVSS 3.1
EPSS 0.60%
描述
A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.
如何修補 CVE-2024-43426
要修補 CVE-2024-43426,請將受影響套件升級到下列已修補版本。
- Bitnami/moodle—升級至 4.1.12 或更新版本
- —升級至 4.1.12 或更新版本
CVE-2024-43426 正在被利用嗎?
低 — EPSS 為 0.6%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- >= 4.1.0, < 4.1.12, >= 4.2.0, < 4.2.9, >= 4.3.0, < 4.3.6, >= 4.4.0, < 4.4.2
- from 0, < 4.1.12
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U |
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |