Multiple security fixes in Moodle were published. CVE-2015-5264 moodle: Students can re-attempt answering questions in the lesson (MSA-15-0030) Completed and graded lesson activity was not protected against making new attempt to answer some questions. Affected versions are 2.9 to 2.9.1, 2.8 to 2.8.7, 2.7 to 2.7.9 and earlier unsupported versions. Upstream patch: https://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-50516 ------------------------------------------- CVE-2015-5272 moodle: Group access is not properly checked when posting to "all participants" in forum (MSA-15-0031) Group access is not properly checked when posting to "all participants" in forum which allows teacher without accessallgroups can still post to "all participants" and groups they're not members of. Affected versions are 2.7 to 2.7.9 and earlier unsupported versions. Upstream patch: https://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-50576 ------------------------------------------- CVE-2015-5265 moodle: Free access to the file manager in the wiki via text editor (MSA-15-0032) A vulnerability was found in file manager in wiki where users can delete files uploaded by other users in wiki without capability to manage files. Affected versions are 2.9 to 2.9.1, 2.8 to 2.8.7, 2.7 to 2.7.9 and earlier unsupported versions. Upstream patch: https://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-48371 ------------------------------------------- CVE-2015-5266 moodle: Meta course sync enroling suspended students as managers and causing large database growth (MSA-15-0033) On large installations, when sync script takes a long time, suspended students may get assigned a manager role in meta course for several minutes. Affected versions are 2.9 to 2.9.1, 2.8 to 2.8.7, 2.7 to 2.7.9 and earlier unsupported versions. Upstream patch: https://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-50744 ------------------------------------------- CVE-2015-5267 moodle: Vulnerability in password recovery mechanism (MSA-15-0034) A vulnerability in password recovery mechanism was found allowing to guess the password recovery token becasue of php randomization limitations. Affected versions are 2.9 to 2.9.1, 2.8 to 2.8.7, 2.7 to 2.7.9 and earlier unsupported versions. Upstream patch: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-50860 ------------------------------------------- CVE-2015-5268 moodle: Rating component does not check separate groups (MSA-15-0035) When viewing ratings the group access was not properly checked allowing users from other groups to view ratings. Affected versions are 2.9 to 2.9.1, 2.8 to 2.8.7, 2.7 to 2.7.9 and earlier unsupported versions. Upstream patch: https://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-50173 ------------------------------------------- CVE-2015-5265 moodle: XSS in grouping description (MSA-15-0036) Capability to manage groups does not have XSS risk, however it was possible to add XSS to the grouping description. Affected versions are 2.9 to 2.9.1, 2.8 to 2.8.7, 2.7 to 2.7.9 and earlier unsupported versions. Upstream patch: https://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-50709 Source: http://seclists.org/oss-sec/2015/q3/595
*** Bug 1264818 has been marked as a duplicate of this bug. ***
*** Bug 1264823 has been marked as a duplicate of this bug. ***
*** Bug 1264826 has been marked as a duplicate of this bug. ***
*** Bug 1264828 has been marked as a duplicate of this bug. ***
*** Bug 1264852 has been marked as a duplicate of this bug. ***
*** Bug 1264858 has been marked as a duplicate of this bug. ***
Created moodle tracking bugs for this issue: Affects: fedora-all [bug 1264868] Affects: epel-6 [bug 1264869]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.