The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://moodle.org/mod/forum/discuss.php?d=459500 |
![]() ![]() |
History
Thu, 01 May 2025 00:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-459 | |
CPEs | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* |

Status: PUBLISHED
Assigner: fedora
Published: 2024-06-18T19:49:26.986Z
Updated: 2024-08-02T04:04:25.068Z
Reserved: 2024-06-12T14:08:44.047Z
Link: CVE-2024-38275

Updated: 2024-07-02T13:43:48.130Z

Status : Analyzed
Published: 2024-06-18T20:15:13.970
Modified: 2025-04-30T23:35:59.790
Link: CVE-2024-38275

No data.