Bug 2121360 (CVE-2022-2986)

Summary: CVE-2022-2986 moodle: CSRF risk in enabling/disabling installed H5P libraries
Product: [Other] Security Response Reporter: Sandipan Roy <saroy>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED UPSTREAM QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: gwync, security-response-team, sergio
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: moodle 4.0.3 and moodle 3.11.9 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-09-03 00:25:48 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2122182, 2122181    
Bug Blocks: 2121356    

Description Sandipan Roy 2022-08-25 08:53:28 UTC
==============================================================================
MSA-22-0022: CSRF risk in enabling/disabling installed H5P libraries

Description:       Enabling and disabling installed H5P libraries did not
                   include the necessary token to prevent a CSRF risk.
Issue summary:     CSRF risk in enabling/disabling installed H5P libraries
Severity/Risk:     Minor
Versions affected: 4.0 to 4.0.2 and 3.11 to 3.11.8
Versions fixed:    4.0.3 and 3.11.9
Reported by:       Paul Holden
Issue no.:         MDL-75326
CVE identifier:    Pending
Changes (master):
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-75326

==============================================================================

Comment 1 Sandipan Roy 2022-08-29 12:54:21 UTC
Created moodle tracking bugs for this issue:

Affects: epel-all [bug 2122182]
Affects: fedora-all [bug 2122181]

Comment 2 Sandipan Roy 2022-08-29 12:55:39 UTC
Issue is Public Now
https://moodle.org/mod/forum/discuss.php?d=437685

Comment 3 Product Security DevOps Team 2022-09-03 00:25:46 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.