The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
{
"nvd_published_at": "2024-06-18T20:15:13Z",
"cwe_ids": [
"CWE-226",
"CWE-459"
],
"severity": "MODERATE",
"github_reviewed_at": "2024-06-18T22:45:35Z",
"github_reviewed": true
}