Vulnerability Bulletins

MSA-22-0021: Upgrade Mustache to latest version (upstream)


System information

   
Affected software PHP

Description

di Michael Hawkins. The Mustache template library included with Moodle has been upgraded to the latest version, which includes a fix for a serious security issue.Severity/Risk:SeriousVersions affected:4.0 to 4.0.2, 3.11 to 3.11.8, 3.9 to 3.9.15 and earlier unsupported versionsVersions fixed:4.0.3, 3.11.9 and 3.9.16Reported by:Lars BonczekCVE identifier:CVE-2022-0323Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-75388Tracker issue:MDL-75388

More info:

https://moodle.org/mod/forum/discuss.php?d=437684&parent=1761481

Standar resources

Property Value
CVE CVE-2022-0323.

Version history

Version Comments Date
1.0 Advisory issued 2022-10-01
Ministerio de Defensa
CNI
CCN
CCN-CERT