Candidate: CVE-2020-25629 PublicDate: 2020-12-08 01:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25629 https://moodle.org/mod/forum/discuss.php?d=410841 Description: A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some site administration capabilities by "logging in as" a System manager. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. This is fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_moodle: upstream_moodle: needs-triage precise/esm_moodle: DNE trusty_moodle: ignored (out of standard support) trusty/esm_moodle: DNE xenial_moodle: ignored (end of standard support, was needs-triage) bionic_moodle: needs-triage focal_moodle: DNE groovy_moodle: DNE hirsute_moodle: DNE impish_moodle: DNE jammy_moodle: DNE devel_moodle: DNE