Boletines de Vulnerabilidades

MSA-18-0014: Privacy data exports include log data


Información sobre el sistema

   
Software afectado PHP

Descripción

di Michael Hawkins. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester. Note this may be a serious privacy consideration for sites processing data exports.Severity/Risk:MinorVersions affected:3.5, 3.4.3, 3.3 to 3.3.6Versions fixed:3.5.1, 3.4.4, 3.3.7Reported by:Ralf HilgenstockCVE identifier:CVE-2018-10889Changes

More info:

https://moodle.org/mod/forum/discuss.php?d=373369&parent=1505292

Identificadores estándar

Propiedad Valor
CVE CVE-2018-10889.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2018-11-16

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT