Fedora Account System
Red Hat Associate
Red Hat Customer
The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs. Issue summary: HTTP authorization header is preserved between "emulated redirects" Severity/Risk: Minor Versions affected: 4.4, 4.3 to 4.3.4, 4.2 to 4.2.7, 4.1 to 4.1.10 and earlier unsupported versions Versions fixed: 4.4.1, 4.3.5, 4.2.8 and 4.1.11 Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-81774
Created moodle tracking bugs for this issue: Affects: epel-all [bug 2292948] Affects: fedora-all [bug 2292949]