The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
History

Thu, 01 May 2025 00:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-459
CPEs cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published: 2024-06-18T19:49:26.986Z

Updated: 2024-08-02T04:04:25.068Z

Reserved: 2024-06-12T14:08:44.047Z

Link: CVE-2024-38275

cve-icon Vulnrichment

Updated: 2024-07-02T13:43:48.130Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-18T20:15:13.970

Modified: 2025-04-30T23:35:59.790

Link: CVE-2024-38275

cve-icon Redhat

No data.