Inclusion of Sensitive Information in Log Files in Moodle - CVE-2018-10889

 

Inclusion of Sensitive Information in Log Files in Moodle - CVE-2018-10889

Published: July 10, 2018 / Updated: July 17, 2020


Vulnerability identifier: #VU31272
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10889
CWE-ID: CWE-532
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester.


Affected software

Moodle
Fedora
moodle

How to mitigate CVE-2018-10889

Install update from vendor's website.

Moodle - update to 3.5.1
moodle - addressed in versions 3.1.13-1.el7, 3.1.13-2.el7, 3.3.7-1.fc27, 3.4.4-1.fc28

External References

Related Security Bulletins