4.5.5. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-83ab16425f 2025-06-29 01:03:14.526427+00:00 -------------------------------------------------------------------------------- Name : moodle Product : Fedora 42 Version : 4.5.5 Release : 1.fc42 URL : https://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) - a free, Open Source software package designed using sound pedagogical principles, to help educators create effective online learning communities. -------------------------------------------------------------------------------- Update Information: 4.5.5 -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 19 2025 Gwyn Ciesla - 4.5.5-1 - 4.5.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2373852 - CVE-2025-49518 moodle: IDOR allows fetching of recently accessed courses for other users via web service [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373852 [ 2 ] Bug #2373856 - CVE-2025-49513 moodle: Password can be revealed in login page after log out due to caching [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373856 [ 3 ] Bug #2373859 - CVE-2025-49514 moodle: SSRF risk via DNS rebind [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373859 [ 4 ] Bug #2373861 - CVE-2025-49515 moodle: Course visibility not honoured consistently [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373861 [ 5 ] Bug #2373862 - CVE-2025-49516 moodle: CSRF risk in badges backpack management [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373862 [ 6 ] Bug #2373864 - CVE-2025-49517 moodle: Missing authorisation checks in BigBlueButton view page [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373864 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-83ab16425f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Latest updates.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-edd8ed2afc 2025-04-23 02:12:49.731534+00:00 -------------------------------------------------------------------------------- Name : moodle Product : Fedora 41 Version : 4.4.8 Release : 1.fc41 URL : https://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) - a free, Open Source software package designed using sound pedagogical principles, to help educators create effective online learning communities. -------------------------------------------------------------------------------- Update Information: Latest updates. -------------------------------------------------------------------------------- ChangeLog: * Mon Apr 14 2025 Gwyn Ciesla - 4.4.8-1 - 4.4.8 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2361646 - CVE-2025-3647 moodle: IDOR when accessing the cohorts report [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2361646 [ 2 ] Bug #2361649 - CVE-2025-3645 moodle: IDOR in messaging web service allows access to some user details [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2361649 [ 3 ] Bug #2361652 - CVE-2025-3644 moodle: AJAX section delete does not respect course_can_delete_section() [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2361652 [ 4 ] Bug #2361655 - CVE-2025-3643 moodle: Reflected XSS risk in policy tool [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2361655 [ 5 ] Bug #2361658 - CVE-2025-3642 moodle: Authenticated remote code execution risk in the Moodle LMS EQUELLA repository [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2361658 [ 6 ] Bug #2361661 - CVE-2025-3641 moodle: Authenticated remote code execution risk in the Moodle LMS Dropbox repository [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2361661 [ 7 ] Bug #2361664 - CVE-2025-3638 moodle: CSRF risk in Brickfield tool's analysis request action [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2361664 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-edd8ed2afc' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fixes for multiple CVEs. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-f7fdcb1820 2022-12-07 01:41:55.062314 --------------------------------------------------------------------------------Name : moodle Product : Fedora 36 Version : 3.11.11 Release : 1.fc36 URL : https://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) - a free, Open Source software package designed using sound pedagogical principles, to help educators create effective online learning communities. --------------------------------------------------------------------------------Update Information: Fixes for multiple CVEs --------------------------------------------------------------------------------ChangeLog: * Mon Nov 28 2022 Gwyn Ciesla - 3.11.11-1 - 3.11.11 --------------------------------------------------------------------------------References: [ 1 ] Bug #2144705 - CVE-2021-23414 CVE-2022-45149 CVE-2022-45150 CVE-2022-45151 CVE-2022-45152 moodle: various flaws [fedora-35] https://bugzilla.redhat.com/show_bug.cgi?id=2144705 [ 2 ] Bug #2144706 - CVE-2021-23414 CVE-2022-45149 CVE-2022-45150 CVE-2022-45151 CVE-2022-45152 moodle: various flaws [fedora-36] https://bugzilla.redhat.com/show_bug.cgi?id=2144706 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-f7fdcb1820' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Fixes for multiple CVEs. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-74a9c8e95f 2022-12-07 01:34:05.124035 --------------------------------------------------------------------------------Name : moodle Product : Fedora 37 Version : 4.1 Release : 1.fc37 URL : https://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) - a free, Open Source software package designed using sound pedagogical principles, to help educators create effective online learning communities. --------------------------------------------------------------------------------Update Information: Fixes for multiple CVEs --------------------------------------------------------------------------------ChangeLog: * Mon Nov 28 2022 Gwyn Ciesla - 4.1.0-1 - 4.1.0 --------------------------------------------------------------------------------References: [ 1 ] Bug #2144705 - CVE-2021-23414 CVE-2022-45149 CVE-2022-45150 CVE-2022-45151 CVE-2022-45152 moodle: various flaws [fedora-35] https://bugzilla.redhat.com/show_bug.cgi?id=2144705 [ 2 ] Bug #2144706 - CVE-2021-23414 CVE-2022-45149 CVE-2022-45150 CVE-2022-45151 CVE-2022-45152 moodle: various flaws [fedora-36] https://bugzilla.redhat.com/show_bug.cgi?id=2144706 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-74a9c8e95f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Latest update.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-50c091d963 2022-09-21 01:21:16.550072 --------------------------------------------------------------------------------Name : moodle Product : Fedora 35 Version : 3.11.10 Release : 1.fc35 URL : https://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) - a free, Open Source software package designed using sound pedagogical principles, to help educators create effective online learning communities. --------------------------------------------------------------------------------Update Information: Latest update. --------------------------------------------------------------------------------ChangeLog: * Mon Sep 12 2022 Gwyn Ciesla - 3.11.10-1 - 3.11.10 --------------------------------------------------------------------------------References: [ 1 ] Bug #2126857 - CVE-2021-36568 www-apps/moodle: XSS via crafted topic fields https://bugzilla.redhat.com/show_bug.cgi?id=2126857 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-50c091d963' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Multiple CVE fixes.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-530fdc5202 2022-05-27 01:11:57.957539 --------------------------------------------------------------------------------Name : moodle Product : Fedora 35 Version : 3.11.7 Release : 1.fc35 URL : https://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) - a free, Open Source software package designed using sound pedagogical principles, to help educators create effective online learning communities. --------------------------------------------------------------------------------Update Information: Multiple CVE fixes. --------------------------------------------------------------------------------ChangeLog: * Wed May 18 2022 Gwyn Ciesla - 3.11.7-1 - 3.11.7 --------------------------------------------------------------------------------References: [ 1 ] Bug #2087632 - CVE-2022-30596 moodle: Stored XSS in assignment bulk marker allocation form via user ID number [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2087632 [ 2 ] Bug #2087633 - CVE-2022-30597 moodle: Description field hidden by user policies (hiddenuserfields) is still visible [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2087633 [ 3 ] Bug #2087634 - CVE-2022-30599 moodle: SQL injection risk in badge award criteria [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2087634 [ 4 ] Bug #2087635 - CVE-2022-30600 moodle: Failed login attempts counted incorrectly [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2087635 [ 5 ] Bug #2087636 - CVE-2022-30598 moodle: global search results reveal authors of content unexpectedly for some activities [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2087636 --------------------------------------------------------------------------------This update can be installed with the"dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-530fdc5202' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
3.11.6. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-09abde662f 2022-03-22 03:40:08.822733 --------------------------------------------------------------------------------Name : moodle Product : Fedora 35 Version : 3.11.6 Release : 1.fc35 URL : https://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) - a free, Open Source software package designed using sound pedagogical principles, to help educators create effective online learning communities. --------------------------------------------------------------------------------Update Information: 3.11.6 --------------------------------------------------------------------------------ChangeLog: * Mon Mar 14 2022 Gwyn Ciesla - 3.11.6-1 - 3.11.6 * Thu Jan 20 2022 Fedora Release Engineering - 3.11.5-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2063394 - moodle-3.11.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=2063394 [ 2 ] Bug #2064123 - CVE-2022-0985 moodle: Users with moodle/site:uploadusers but without moodle/user:delete could delete users [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2064123 [ 3 ] Bug #2064125 - CVE-2022-0984 moodle: possible to reach the profile field badge criteria on a course page [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2064125 [ 4 ] Bug #2064126 - CVE-2022-0983 moodle: SQL injection risk in badges criteria code [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2064126 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-09abde662f' at the command line. For more information, refer to the dnfdocumentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Fixes for multiple CVEs. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-50f63a0161 2021-03-23 01:10:40.843751 --------------------------------------------------------------------------------Name : moodle Product : Fedora 32 Version : 3.8.8 Release : 1.fc32 URL : https://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) - a free, Open Source software package designed using sound pedagogical principles, to help educators create effective online learning communities. --------------------------------------------------------------------------------Update Information: Fixes for multiple CVEs --------------------------------------------------------------------------------ChangeLog: * Mon Mar 15 2021 Gwyn Ciesla - 3.8.8-1 - 3.8.8 --------------------------------------------------------------------------------References: [ 1 ] Bug #1939035 - CVE-2021-20279 moodle: Stored XSS via ID number user profile field [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1939035 [ 2 ] Bug #1939039 - CVE-2021-20280 moodle: Stored XSS and blind SSRF possible via feedback answer text [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1939039 [ 3 ] Bug #1939047 - CVE-2021-20281 moodle: User full name disclosure within online users block [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1939047 [ 4 ] Bug #1939049 - CVE-2021-20282 moodle: Bypass email verification secret when confirming account registration [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1939049 [ 5 ] Bug #1939053 - CVE-2021-20283 moodle: Fetching a user's enrolled courses via web services did not check profile access in each course [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1939053 --------------------------------------------------------------------------------This update can beinstalled with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-50f63a0161' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.