Bug 1895432 (CVE-2020-25701)
| Summary: | CVE-2020-25701 moodle: tool_uploadcourse creates new enrol instances unexpectedly in some circumstances | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Michael Kaplan <mkaplan> | 
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | 
| Status: | CLOSED UPSTREAM | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | gwync, igor.raits, security-response-team, sergio | 
| Target Milestone: | --- | Keywords: | Security | 
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | moodle 3.9.3, moodle 3.8.6, moodle 3.7.9, moodle 3.5.15, moodle 3.10 | Doc Type: | If docs needed, set a value | 
| Doc Text: | If the upload course tool was used to delete an enrolment method which did not exist or was not already enabled, the tool would erroneously enable that enrolment method. This could lead to unintended users gaining access to the course. | Story Points: | --- | 
| Clone Of: | Environment: | ||
| Last Closed: | 2020-11-19 17:28:42 UTC | Type: | --- | 
| Regression: | --- | Mount Type: | --- | 
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1899541, 1899542 | ||
| Bug Blocks: | |||
| 
        
          Description
        
        
          Michael Kaplan
        
        
        
        
        
          2020-11-06 16:40:09 UTC
        
       Acknowledgments: Name: Víctor Déniz Falcón External References: https://moodle.org/mod/forum/discuss.php?d=413939 Created moodle tracking bugs for this issue: Affects: epel-all [bug 1899541] Affects: fedora-all [bug 1899542] This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products. |