Bug 2494834 (CVE-2026-58346)
| Summary: | CVE-2026-58346 moodle: Blind SSRF risk in MNet peers function | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | security-response-team |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Moodle. A site administrator could exploit a blind Server-Side Request Forgery (SSRF) vulnerability. This vulnerability exists in the MNet peers management functionality due to insufficient validation of peer hostnames against the cURL blocked hosts configuration. This could allow an attacker to make the server perform requests to arbitrary domains, potentially leading to information disclosure or other internal network access.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2507962 | ||
| Bug Blocks: | |||
| Deadline: | 2026-07-01 | ||
|
Description
OSIDB Bzimport
2026-06-30 10:36:22 UTC
|