The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://moodle.org/mod/forum/discuss.php?d=459500 |
|
History
Thu, 01 May 2025 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-459 | |
| CPEs | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: fedora
Published: 2024-06-18T19:49:26.986Z
Updated: 2024-08-02T04:04:25.068Z
Reserved: 2024-06-12T14:08:44.047Z
Link: CVE-2024-38275
Updated: 2024-07-02T13:43:48.130Z
Status : Analyzed
Published: 2024-06-18T20:15:13.970
Modified: 2025-04-30T23:35:59.790
Link: CVE-2024-38275
No data.