Vulnerability Description
In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being shown for the institution that the viewer is a member of).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mahara | Mahara | < 20.10.5 |
Related Weaknesses (CWE)
References
- https://bugs.launchpad.net/mahara/+bug/1922226Vendor Advisory
- https://mahara.org/interaction/forum/topic.php?id=9093Vendor Advisory
- https://bugs.launchpad.net/mahara/+bug/1922226Vendor Advisory
- https://mahara.org/interaction/forum/topic.php?id=9093Vendor Advisory
FAQ
What is CVE-2022-29585?
CVE-2022-29585 is a vulnerability with a CVSS score of 7.5 (HIGH). In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (ra...
How severe is CVE-2022-29585?
CVE-2022-29585 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-29585?
Check the references section above for vendor advisories and patch information. Affected products include: Mahara Mahara.