Bug 2142772 (CVE-2022-45149, MSA-22-0029)

Summary: CVE-2022-45149 moodle: course restore - CSRF token passed in course redirect URL
Product: [Other] Security Response Reporter: TEJ RATHI <trathi>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED UPSTREAM QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: moodle 4.0.5, moodle 3.11.11, moodle 3.9.18 Doc Type: If docs needed, set a value
Doc Text:
A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included in the URL when being redirected to a course they have just restored. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website. This flaw allows an attacker to perform cross-site request forgery attacks.
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-12-07 18:32:52 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2144704, 2144705, 2144706, 2144707    
Bug Blocks: 2141946, 2144717    

Description TEJ RATHI 2022-11-15 08:58:25 UTC
MSA-22-0029: Course restore - CSRF token passed in course redirect URL

A user's CSRF token (Moodle sesskey) was unnecessarily included in the URL when being redirected to a course they have just restored.

Versions affected: 4.0 to 4.0.4, 3.11 to 3.11.10, 3.9 to 3.9.17 and earlier unsupported versions
Versions fixed:    4.0.5, 3.11.11 and 3.9.18

Comment 3 TEJ RATHI 2022-11-22 03:59:44 UTC
Created moodle tracking bugs for this issue:

Affects: epel-7 [bug 2144704]
Affects: fedora-35 [bug 2144705]
Affects: fedora-36 [bug 2144706]
Affects: fedora-37 [bug 2144707]

Comment 4 Product Security DevOps Team 2022-12-07 18:32:51 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.