Boletines de Vulnerabilidades

MSA-22-0032: Blind SSRF risk in LTI provider library


Información sobre el sistema

   
Software afectado PHP

Descripción

by Michael Hawkins. Moodles LTI provider library did not utilise Moodles inbuilt cURL helper, which resulted in a blind SSRF risk.Severity/Risk:SeriousVersions affected:4.0 to 4.0.4, 3.11 to 3.11.10, 3.9 to 3.9.17 and earlier unsupported versionsVersions fixed:4.0.5, 3.11.11 and 3.9.18Reported by:Rekter0 and HolmeCVE identifier:CVE-2022-45152Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-71920Tracker issue:MDL-71920 Blind SSRF risk in LTI

More info:

https://moodle.org/mod/forum/discuss.php?d=440772&parent=1773540

Identificadores estándar

Propiedad Valor
CVE CVE-2022-45152.

Histórico de versiones

Versión Comentario Data
1.0 Advisory issued 2022-11-22
Ministerio de Defensa
CNI
CCN
CCN-CERT