Description
The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p2cj-86v4-7782 | Moodle HTTP authorization header is preserved between "emulated redirects" |
References
| Link | Providers |
|---|---|
| https://moodle.org/mod/forum/discuss.php?d=459500 |
|
History
Thu, 01 May 2025 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-459 | |
| CPEs | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2024-08-02T04:04:25.068Z
Reserved: 2024-06-12T14:08:44.047Z
Link: CVE-2024-38275
Updated: 2024-07-02T13:43:48.130Z
Status : Analyzed
Published: 2024-06-18T20:15:13.970
Modified: 2025-04-30T23:35:59.790
Link: CVE-2024-38275
No data.
OpenCVE Enrichment
No data.
Github GHSA