vuln-list-alt/oval/c10f1/ALT-PU-2019-2248/definitions.json
2024-06-28 13:17:52 +00:00

155 lines
6.0 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20192248",
"Version": "oval:org.altlinux.errata:def:20192248",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2019-2248: package `moodle` update to version 3.7.1-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c10f1"
],
"Products": [
"ALT SP Workstation",
"ALT SP Server"
]
}
],
"References": [
{
"RefID": "ALT-PU-2019-2248",
"RefURL": "https://errata.altlinux.org/ALT-PU-2019-2248",
"Source": "ALTPU"
},
{
"RefID": "BDU:2020-02113",
"RefURL": "https://bdu.fstec.ru/vul/2020-02113",
"Source": "BDU"
},
{
"RefID": "CVE-2019-10186",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-10186",
"Source": "CVE"
},
{
"RefID": "CVE-2019-10187",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-10187",
"Source": "CVE"
},
{
"RefID": "CVE-2019-10188",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-10188",
"Source": "CVE"
},
{
"RefID": "CVE-2019-10189",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-10189",
"Source": "CVE"
}
],
"Description": "This update upgrades moodle to version 3.7.1-alt1. \nSecurity Fix(es):\n\n * BDU:2020-02113: Уязвимость виртуальной обучающей среды moodle, связанная с недостатками контроля доступа, позволяющая нарушителю оказать воздействие на целостность защищаемой информации\n\n * CVE-2019-10186: A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.\n\n * CVE-2019-10187: A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to.\n\n * CVE-2019-10188: A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in the same quiz.\n\n * CVE-2019-10189: A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groups in the same assignment.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2019-07-12"
},
"Updated": {
"Date": "2019-07-12"
},
"BDUs": [
{
"ID": "BDU:2020-02113",
"CVSS": "AV:N/AC:L/Au:S/C:N/I:P/A:N",
"CVSS3": "AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"CWE": "CWE-284",
"Href": "https://bdu.fstec.ru/vul/2020-02113",
"Impact": "Low",
"Public": "20190703"
}
],
"CVEs": [
{
"ID": "CVE-2019-10186",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-352",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-10186",
"Impact": "High",
"Public": "20190731"
},
{
"ID": "CVE-2019-10187",
"CVSS": "AV:N/AC:L/Au:S/C:N/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"CWE": "CWE-862",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-10187",
"Impact": "Low",
"Public": "20190731"
},
{
"ID": "CVE-2019-10188",
"CVSS": "AV:N/AC:L/Au:S/C:N/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"CWE": "NVD-CWE-Other",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-10188",
"Impact": "Low",
"Public": "20190731"
},
{
"ID": "CVE-2019-10189",
"CVSS": "AV:N/AC:L/Au:S/C:N/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"CWE": "NVD-CWE-Other",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-10189",
"Impact": "Low",
"Public": "20190731"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:10",
"cpe:/o:alt:spserver:10"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:4001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20192248001",
"Comment": "moodle is earlier than 0:3.7.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192248002",
"Comment": "moodle-apache2 is earlier than 0:3.7.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192248003",
"Comment": "moodle-base is earlier than 0:3.7.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192248004",
"Comment": "moodle-local-mysql is earlier than 0:3.7.1-alt1"
}
]
}
]
}
}
]
}