Alerts This Week
Warning Icon 1 774
Alerts This Week
Warning Icon 1 774

Fedora 40: 2024-020937763e Moderate: Moodle XSS and CSRF Security Fix

fedora
Calendar Grey June 27, 2024
Dist Fedora Esm H88
The latest Fedora package updates for Moodle version 4.3.5 resolve essential XSS and CSRF vulnerabilities, alongside multiple enhancements and optimizations across the platform.
Fix for multiple CVEs

Summary

Moodle is a course management system (CMS) - a free, Open Source software

package designed using sound pedagogical principles, to help educators create

effective online learning communities.

Update Information:

Fix for multiple CVEs

Change Log

* Tue Jun 18 2024 Gwyn Ciesla - 4.3.5-1 - 4.3.5

References


[ 1 ] Bug #2292945 - CVE-2024-38273 moodle: BigBlueButton web service leaks meeting joining information to users who should not have access [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2292945 [ 2 ] Bug #2292946 - CVE-2024-38274 moodle: stored XSS via calendar's event title when deleting the event [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2292946 [ 3 ] Bug #2292951 - CVE-2024-38276 moodle: CSRF risks due to misuse of confirm_sesskey [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2292951 [ 4 ] Bug #2292953 - CVE-2024-38277 moodle: QR login key and auto-login key for the Moodle mobile app should be generated as separate keys [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2292953

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-020937763e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Name: moodle
Product: Fedora 40
Version: 4.3.5
Release: 1.fc40
Summary: A Course Management System

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here