Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 41: FEDORA-2025-622bed7e7a critical: moodle SSRF and IDOR risks

fedora
Calendar Grey June 29, 2025
Dist Fedora Esm H88
The latest release of Moodle for Fedora 41 tackles significant security vulnerabilities, particularly focusing on SSRF and IDOR concerns.
4.4.9

Summary

Moodle is a course management system (CMS) - a free, Open Source software

package designed using sound pedagogical principles, to help educators create

effective online learning communities.

Update Information:

4.4.9

Change Log

* Thu Jun 19 2025 Gwyn Ciesla - 4.4.9-1 - 4.4.9

References


[ 1 ] Bug #2373851 - CVE-2025-49518 moodle: IDOR allows fetching of recently accessed courses for other users via web service [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2373851 [ 2 ] Bug #2373855 - CVE-2025-49513 moodle: Password can be revealed in login page after log out due to caching [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2373855 [ 3 ] Bug #2373857 - CVE-2025-49514 moodle: SSRF risk via DNS rebind [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2373857 [ 4 ] Bug #2373858 - CVE-2025-49515 moodle: Course visibility not honoured consistently [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2373858 [ 5 ] Bug #2373860 - CVE-2025-49516 moodle: CSRF risk in badges backpack management [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2373860 [ 6 ] Bug #2373863 - CVE-2025-49517 moodle: Missing authorisation checks in BigBlueButton view page [fedora-41] https://bugzill...

Read the Full Advisory

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-622bed7e7a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: moodle
Product: Fedora 41
Version: 4.4.9
Release: 1.fc41
Summary: A Course Management System

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here