Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 42: 2025-83ab16425f critical: moodle web service risks

fedora
Calendar Grey June 29, 2025
Dist Fedora Esm H88
The release of Moodle 4.5.5 for Fedora 42 has been accompanied by a vital security notice detailing several vulnerabilities that necessitate immediate patching.
4.5.5

Summary

Moodle is a course management system (CMS) - a free, Open Source software

package designed using sound pedagogical principles, to help educators create

effective online learning communities.

Update Information:

4.5.5

Change Log

* Thu Jun 19 2025 Gwyn Ciesla - 4.5.5-1 - 4.5.5

References


[ 1 ] Bug #2373852 - CVE-2025-49518 moodle: IDOR allows fetching of recently accessed courses for other users via web service [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373852 [ 2 ] Bug #2373856 - CVE-2025-49513 moodle: Password can be revealed in login page after log out due to caching [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373856 [ 3 ] Bug #2373859 - CVE-2025-49514 moodle: SSRF risk via DNS rebind [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373859 [ 4 ] Bug #2373861 - CVE-2025-49515 moodle: Course visibility not honoured consistently [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373861 [ 5 ] Bug #2373862 - CVE-2025-49516 moodle: CSRF risk in badges backpack management [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373862 [ 6 ] Bug #2373864 - CVE-2025-49517 moodle: Missing authorisation checks in BigBlueButton view page [fedora-42] https://bugzill...

Read the Full Advisory

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-83ab16425f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: moodle
Product: Fedora 42
Version: 4.5.5
Release: 1.fc42
Summary: A Course Management System

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here