CVE-2024-38275

June 18, 2024, 8:15 p.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Moodle

Source

patrick@puiterwijk.org

Tags

CVE-2024-38275 details

Published : June 18, 2024, 8:15 p.m.
Last Modified : June 18, 2024, 8:15 p.m.

Description

The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description
CWE-226 Sensitive Information in Resource Not Removed Before Reuse The product releases a resource such as memory or a file so that it can be made available for reuse, but it does not clear or "zeroize" the information contained in the resource before the product performs a critical state transition or makes the resource available for reuse by other entities.

References

URL Source
https://moodle.org/mod/forum/discuss.php?d=459500 patrick@puiterwijk.org
This website uses the NVD API, but is not approved or certified by it.