Bug 2243453 (CVE-2023-5551, MSA-23-0043) - CVE-2023-5551 moodle: Forum summary report shows students from other groups when in Separate Groups mode
Summary: CVE-2023-5551 moodle: Forum summary report shows students from other groups w...
Keywords:
Status: NEW
Alias: CVE-2023-5551, MSA-23-0043
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2244951 2244952
Blocks: 2243346
TreeView+ depends on / blocked
 
Reported: 2023-10-12 00:54 UTC by Robb Gatica
Modified: 2023-10-26 06:41 UTC (History)
2 users (show)

Fixed In Version: moodle 4.2.3, moodle 4.1.6, moodle 4.0.11, moodle 3.11.17, moodle 3.9.24
Doc Type: If docs needed, set a value
Doc Text:
Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Robb Gatica 2023-10-12 00:54:47 UTC
Separate Groups mode restrictions were not honored in the forum summary report, which would display users from other groups. This flaw affects versions 4.2 to 4.2.2, 4.1 to 4.1.5, 4.0 to 4.0.10, 3.11 to 3.11.16, 3.9 to 3.9.23 and earlier unsupported versions.

Comment 3 Nick Tait 2023-10-18 23:54:45 UTC
Created moodle tracking bugs for this issue:

Affects: epel-7 [bug 2244951]
Affects: fedora-all [bug 2244952]


Note You need to log in before you can comment on or make changes to this bug.