Bug 2128147 (CVE-2022-40314) - CVE-2022-40314 moodle: Remote code execution risk when restoring malformed backup file
Summary: CVE-2022-40314 moodle: Remote code execution risk when restoring malformed ba...
Keywords:
Status: NEW
Alias: CVE-2022-40314
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2125553
TreeView+ depends on / blocked
 
Reported: 2022-09-20 05:17 UTC by Sandipan Roy
Modified: 2023-07-07 08:34 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Sandipan Roy 2022-09-20 05:17:51 UTC
Severity/Risk: 	Serious
Versions affected: 	4.0 to 4.0.3, 3.11 to 3.11.9, 3.9 to 3.9.16 and earlier unsupported versions
Versions fixed: 	4.0.4, 3.11.10 and 3.9.17
Reported by: 	Paul Holden
CVE identifier: 	CVE-2022-40314
Changes (master): 	http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-75405
Tracker issue: 	MDL-75405 Remote code execution risk when restoring malformed backup file from Moodle 1.9


Note You need to log in before you can comment on or make changes to this bug.