CVE-2015-3179
Published: 1 June 2015
login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access to an unconfirmed suspended account.
Priority
Status
Package | Release | Status |
---|---|---|
moodle Launchpad, Ubuntu, Debian |
artful |
Ignored
(end of life)
|
bionic |
Not vulnerable
(3.0.3+dfsg-0ubuntu1)
|
|
cosmic |
Not vulnerable
(3.0.3+dfsg-0ubuntu1)
|
|
disco |
Not vulnerable
(3.0.3+dfsg-0ubuntu1)
|
|
precise |
Ignored
(end of life)
|
|
trusty |
Does not exist
(trusty was needed)
|
|
upstream |
Released
(2.9, 2.8.6, 2.7.8 and 2.6.11)
|
|
utopic |
Ignored
(end of life)
|
|
wily |
Ignored
(end of life)
|
|
xenial |
Not vulnerable
(3.0.3+dfsg-0ubuntu1)
|
|
yakkety |
Ignored
(end of life)
|
|
zesty |
Ignored
(end of life)
|
|
vivid |
Ignored
(end of life)
|
|
Patches: upstream: http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=f236dcc35c3595dfcc77932d84660056e982a310 |