An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.
References
Configurations
Configuration 1 (hide)
|
History
19 Apr 2024, 14:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
07 Nov 2023, 04:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
30 Jun 2023, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
29 Jun 2023, 20:27
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-918 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CPE | cpe:2.3:a:moodle:moodle:4.2.0:*:*:*:*:*:*:* cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* |
|
References | (MISC) https://moodle.org/mod/forum/discuss.php?d=447831 - Patch, Vendor Advisory | |
First Time |
Moodle moodle
Moodle |
22 Jun 2023, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-22 21:15
Updated : 2024-04-19 14:15
NVD link : CVE-2023-35133
Mitre link : CVE-2023-35133
CVE.ORG link : CVE-2023-35133
JSON object : View
Products Affected
moodle
- moodle
CWE
CWE-918
Server-Side Request Forgery (SSRF)