BIT-moodle-2024-38273

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/moodle/BIT-moodle-2024-38273.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-moodle-2024-38273
Aliases
Published
2025-08-08T06:00:26.723Z
Modified
2025-08-08T07:27:07.101427Z
Summary
moodle: BigBlueButton web service leaks meeting joining information to users who should not have access
Details

Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.

Database specific
{
    "cpes": [
        "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / moodle

Package

Name
moodle
Purl
pkg:bitnami/moodle

Severity

  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
4.1.0
Fixed
4.1.11
Introduced
4.2.0
Fixed
4.2.8
Introduced
4.3.0
Fixed
4.3.5
Introduced
4.4.0
Fixed
4.4.1