{
  "schema_version": "1.7.0",
  "id": "MGASA-2014-0230",
  "published": "2014-05-19T18:46:11Z",
  "modified": "2014-05-19T18:45:34Z",
  "summary": "Updated moodle packages fix multiple vulnerabilities",
  "details": "Updated moodle package fixes security vulnerabilities:\n\nIn Moodle before 2.6.3, Session checking was not being performed correctly\nin Assignment's quick-grading, allowing forged requests to be made\nunknowingly by authenticated users (CVE-2014-0213).\n\nIn Moodle before 2.6.3, MoodleMobile web service tokens, created\nautomatically in login/token.php, were not expiring and were valid forever\n(CVE-2014-0214).\n\nIn Moodle before 2.6.3, Some student details, including identities, were\nincluded in assignment marking pages and would have been revealed to\nscreen readers or through code inspection (CVE-2014-0215).\n\nIn Moodle before 2.6.3, Access to files linked on HTML blocks on the My\nhome page was not being checked in the correct context, allowing access to\nunauthenticated users (CVE-2014-0216).\n\nIn Moodle before 2.6.3, There was a lack of filtering in the URL\ndownloader repository that could have been exploited for XSS\n(CVE-2014-0218).\n\nThe 2.4 branch of Moodle will no longer be supported as of approximately\nJune 2014, so the Moodle package has been upgraded to version 2.6.3 to fix\nthese issues.\n",
  "upstream": [
    "CVE-2014-0213",
    "CVE-2014-0214",
    "CVE-2014-0215",
    "CVE-2014-0216",
    "CVE-2014-0218"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2014-0230.html"
    },
    {
      "type": "WEB",
      "url": "https://moodle.org/mod/forum/discuss.php?d=260361"
    },
    {
      "type": "WEB",
      "url": "https://moodle.org/mod/forum/discuss.php?d=260362"
    },
    {
      "type": "WEB",
      "url": "https://moodle.org/mod/forum/discuss.php?d=260363"
    },
    {
      "type": "WEB",
      "url": "https://moodle.org/mod/forum/discuss.php?d=260364"
    },
    {
      "type": "WEB",
      "url": "https://moodle.org/mod/forum/discuss.php?d=260366"
    },
    {
      "type": "WEB",
      "url": "http://docs.moodle.org/dev/Moodle_2.4.10_release_notes"
    },
    {
      "type": "WEB",
      "url": "http://docs.moodle.org/dev/Moodle_2.6.3_release_notes"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=13369"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:3",
        "name": "moodle",
        "purl": "pkg:rpm/mageia/moodle?arch=source&distro=mageia-3"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2.6.3-1.mga3"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:4",
        "name": "moodle",
        "purl": "pkg:rpm/mageia/moodle?arch=source&distro=mageia-4"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2.6.3-1.mga4"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
