CVE-2024-38275

Source
https://cve.org/CVERecord?id=CVE-2024-38275
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-38275.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-38275
Aliases
Downstream
Published
2024-06-18T20:15:13.970Z
Modified
2026-02-03T07:37:39.131114Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

References

Affected packages

Git / github.com/moodle/moodle

Affected versions

v4.*
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.3.0
v4.3.0-beta
v4.3.0-rc1
v4.3.0-rc2
v4.3.1
v4.3.2
v4.3.3
v4.3.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-38275.json"