123 lines
3.9 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2011-4300",
"sourceIdentifier": "secalert@redhat.com",
"published": "2012-07-11T10:26:10.797",
"lastModified": "2023-02-13T04:32:47.070",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which allows remote attackers to obtain potentially sensitive information via a request for a file."
},
{
"lang": "es",
"value": "El componente file_browser en Moodle v2.0.x antes de v2.0.5 y v2.1.x antes de v2.1.2 no restringe debidamente el acceso a los datos de categor\u00eda y curso, lo que permite a atacantes remotos obtener informaci\u00f3n sensible a trav\u00e9s de una solicitud de un archivo."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:2.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "DD248A1D-CACC-4E76-925A-078B736442AE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:2.0.1:*:*:*:*:*:*:*",
"matchCriteriaId": "9B8A0403-0869-495F-B7C0-13A387549C7A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:2.0.2:*:*:*:*:*:*:*",
"matchCriteriaId": "39791F43-CF89-485B-AA8B-634C282BB025"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:2.0.3:*:*:*:*:*:*:*",
"matchCriteriaId": "428E4846-8C9E-4592-8437-88FCDCED704D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:2.0.4:*:*:*:*:*:*:*",
"matchCriteriaId": "A4096977-3258-48B0-9C7B-D43FBC8BB1EA"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:2.1.0:*:*:*:*:*:*:*",
"matchCriteriaId": "18C6F348-DAE9-4440-8B3A-8D92ADC6606F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:2.1.1:*:*:*:*:*:*:*",
"matchCriteriaId": "367537BF-CBDF-4CBB-91B4-6E5A567EF605"
}
]
}
]
}
],
"references": [
{
"url": "http://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=f6b07c4da54a9db24723beb147e8a19a3d487e00",
"source": "secalert@redhat.com"
},
{
"url": "http://moodle.org/mod/forum/discuss.php?d=188311",
"source": "secalert@redhat.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=747444",
"source": "secalert@redhat.com",
"tags": [
"Patch"
]
}
]
}