In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-8642.json"