Inclusion of Sensitive Information in Log Files in Moodle - CVE-2018-10889
Published: July 10, 2018 / Updated: July 17, 2020
Vulnerability identifier: #VU31272
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10889
CWE-ID: CWE-532
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester.
Affected software
Moodle
Fedora
moodle
Fedora
moodle
How to mitigate CVE-2018-10889
Install update from vendor's website.
Moodle - update to 3.5.1
moodle - addressed in versions 3.1.13-1.el7, 3.1.13-2.el7, 3.3.7-1.fc27, 3.4.4-1.fc28
moodle - addressed in versions 3.1.13-1.el7, 3.1.13-2.el7, 3.3.7-1.fc27, 3.4.4-1.fc28