Vulnerability Description
A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Moodle | Moodle | < 4.1.12 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2304260Permissions Required
- https://moodle.org/mod/forum/discuss.php?d=461200Vendor Advisory
FAQ
What is CVE-2024-43432?
CVE-2024-43432 is a vulnerability with a CVSS score of 5.3 (MEDIUM). A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header informati...
How severe is CVE-2024-43432?
CVE-2024-43432 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-43432?
Check the references section above for vendor advisories and patch information. Affected products include: Moodle Moodle.