137 lines
5.1 KiB
JSON
137 lines
5.1 KiB
JSON
{
|
|
"Definition": [
|
|
{
|
|
"ID": "oval:org.altlinux.errata:def:20201977",
|
|
"Version": "oval:org.altlinux.errata:def:20201977",
|
|
"Class": "patch",
|
|
"Metadata": {
|
|
"Title": "ALT-PU-2020-1977: package `moodle` update to version 3.8.3-alt1",
|
|
"AffectedList": [
|
|
{
|
|
"Family": "unix",
|
|
"Platforms": [
|
|
"ALT Linux branch c9f2"
|
|
],
|
|
"Products": [
|
|
"ALT SPWorkstation",
|
|
"ALT SPServer"
|
|
]
|
|
}
|
|
],
|
|
"References": [
|
|
{
|
|
"RefID": "ALT-PU-2020-1977",
|
|
"RefURL": "https://errata.altlinux.org/ALT-PU-2020-1977",
|
|
"Source": "ALTPU"
|
|
},
|
|
{
|
|
"RefID": "CVE-2020-10738",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-10738",
|
|
"Source": "CVE"
|
|
},
|
|
{
|
|
"RefID": "CVE-2020-1754",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-1754",
|
|
"Source": "CVE"
|
|
},
|
|
{
|
|
"RefID": "CVE-2020-1755",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-1755",
|
|
"Source": "CVE"
|
|
},
|
|
{
|
|
"RefID": "CVE-2020-1756",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-1756",
|
|
"Source": "CVE"
|
|
}
|
|
],
|
|
"Description": "This update upgrades moodle to version 3.8.3-alt1. \nSecurity Fix(es):\n\n * CVE-2020-10738: A flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12 and earlier unsupported versions. It was possible to create a SCORM package in such a way that when added to a course, it could be interacted with via web services in order to achieve remote code execution.\n\n * CVE-2020-1754: In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.\n\n * CVE-2020-1755: In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.\n\n * CVE-2020-1756: In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.",
|
|
"Advisory": {
|
|
"From": "errata.altlinux.org",
|
|
"Severity": "High",
|
|
"Rights": "Copyright 2024 BaseALT Ltd.",
|
|
"Issued": {
|
|
"Date": "2020-05-18"
|
|
},
|
|
"Updated": {
|
|
"Date": "2020-05-18"
|
|
},
|
|
"BDUs": null,
|
|
"CVEs": [
|
|
{
|
|
"ID": "CVE-2020-10738",
|
|
"CVSS": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
|
|
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
|
|
"CWE": "CWE-20",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-10738",
|
|
"Impact": "High",
|
|
"Public": "20200521"
|
|
},
|
|
{
|
|
"ID": "CVE-2020-1754",
|
|
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
|
|
"CWE": "CWE-732",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-1754",
|
|
"Impact": "Low",
|
|
"Public": "20220805"
|
|
},
|
|
{
|
|
"ID": "CVE-2020-1755",
|
|
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
|
|
"CWE": "CWE-345",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-1755",
|
|
"Impact": "Low",
|
|
"Public": "20220816"
|
|
},
|
|
{
|
|
"ID": "CVE-2020-1756",
|
|
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
|
|
"CWE": "CWE-20",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-1756",
|
|
"Impact": "High",
|
|
"Public": "20220816"
|
|
}
|
|
],
|
|
"AffectedCPEs": {
|
|
"CPEs": [
|
|
"cpe:/o:alt:spworkstation:8.4",
|
|
"cpe:/o:alt:spserver:8.4"
|
|
]
|
|
}
|
|
}
|
|
},
|
|
"Criteria": {
|
|
"Operator": "AND",
|
|
"Criterions": [
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:3001",
|
|
"Comment": "ALT Linux must be installed"
|
|
}
|
|
],
|
|
"Criterias": [
|
|
{
|
|
"Operator": "OR",
|
|
"Criterions": [
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20201977001",
|
|
"Comment": "moodle is earlier than 0:3.8.3-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20201977002",
|
|
"Comment": "moodle-apache2 is earlier than 0:3.8.3-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20201977003",
|
|
"Comment": "moodle-base is earlier than 0:3.8.3-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20201977004",
|
|
"Comment": "moodle-local-mysql is earlier than 0:3.8.3-alt1"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
} |