Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 40: 2024-bdda1791b5 moderate: moodle security updates

fedora
Calendar Grey December 27, 2024
Dist Fedora Esm H88
Numerous vulnerabilities addressed in Moodle on Fedora 40 enhance safety and mitigate significant threats impacting course administration.
Multiple CVE fixes

Summary

Moodle is a course management system (CMS) - a free, Open Source software

package designed using sound pedagogical principles, to help educators create

effective online learning communities.

Update Information:

Multiple CVE fixes

Change Log

* Tue Dec 17 2024 Gwyn Ciesla - 4.3.9-1 - 4.3.9

References


[ 1 ] Bug #2332795 - CVE-2024-55648 moodle: Potential denial of service risk due to guest sessions' longer timeout period [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2332795 [ 2 ] Bug #2332811 - CVE-2024-55647 moodle: Reflected XSS in question bank filter [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2332811 [ 3 ] Bug #2332813 - CVE-2024-55646 moodle: Database activity issue in separate groups mode, for users not in a group [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2332813 [ 4 ] Bug #2332823 - CVE-2024-55645 moodle: Email change confirmation token available via preference [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2332823 [ 5 ] Bug #2332825 - CVE-2024-55644 moodle: Tag index page displays other users tagged with the selected tag [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2332825 [ 6 ] Bug #2332827 - CVE-2024-55643 moodle: Unprotected access to sensitive informa...

Read the Full Advisory

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-bdda1791b5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Name: moodle
Product: Fedora 40
Version: 4.3.9
Release: 1.fc40
Summary: A Course Management System

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here