CVE-2020-9387

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-9387
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-9387.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-9387
Published
2020-04-30T13:15:13.460Z
Modified
2025-11-14T11:10:22.905655Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' is turned on.

References

Affected packages

Git / github.com/maharaproject/mahara

Affected ranges

Type
GIT
Repo
https://github.com/maharaproject/mahara
Events

Affected versions

19.*

19.04.0_RELEASE
19.04.1_RELEASE
19.04.2_RELEASE
19.04.3_RELEASE
19.04.4_RELEASE