Vulnerability Bulletins

MSA-17-0006: User fullname disclosure on user preferences page

   
Affected software PHP
 
by Marina Glancy. Some pages show full names of users as part of the permission error message even for users who do not have capability to view full namesSeverity/Risk:MinorVersions affected:3.3, 3.2 to 3.2.3, 3.1 to 3.1.6 and earlier unsupported versionsVersions fixed:3.3.1, 3.2.4 and 3.1.7Reported by:Andreas GrabsCVE identifier:CVE-2017-2642Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-56565Tracker issue:MDL-56565 User fullname

More info:

https://moodle.org/mod/forum/discuss.php?d=355554&parent=1434234