Boletines de Vulnerabilidades

MSA-18-0012: Portfolio script allows instantiation of class chosen by user


Información sobre el sistema

   
Software afectado PHP

Descripción

di Marina Glancy. Substituting URL in portfolios users can instantiate any class, this can also be exploited by users who are logged in as guests to create a DDoS attackSeverity/Risk:SeriousVersions affected:3.4 to 3.4.2, 3.3 to 3.3.5, 3.2 to 3.2.8, 3.1 to 3.1.11 and earlier unsupported versionsVersions fixed:3.5, 3.4.3, 3.3.6, 3.2.9 and 3.1.12Reported by:Brendan CoxWorkaround:Disable portfolios until the fix is applied. Portfolios are disabled by default in MoodleCVE

More info:

https://moodle.org/mod/forum/discuss.php?d=371204&parent=1496358

Identificadores estándar

Propiedad Valor
CVE CVE-2018-1137.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2018-11-16

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT