A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities Upstream Bug: https://tracker.moodle.org/browse/MDL-64410 Upstream Patch: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-64410
Acknowledgments: Name: Andrew Nicols
External References: https://moodle.org/mod/forum/discuss.php?d=384015#p1547748
Created moodle tracking bugs for this issue: Affects: epel-all [bug 1692938] Affects: fedora-all [bug 1692937]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.