Candidate: CVE-2011-4583 PublicDate: 2012-07-20 10:40:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4583 Description: Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=652235 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_moodle: other: http://moodle.org/mod/forum/discuss.php?d=191750 upstream_moodle: needs-triage hardy_moodle: ignored (reached end-of-life) lucid_moodle: ignored (reached end-of-life) maverick_moodle: ignored (reached end-of-life) natty_moodle: ignored (reached end-of-life) oneiric_moodle: ignored (reached end-of-life) precise_moodle: not-affected (1.9.9.dfsg2-5) quantal_moodle: not-affected (1.9.9.dfsg2-5) raring_moodle: not-affected (1.9.9.dfsg2-5) saucy_moodle: not-affected (1.9.9.dfsg2-5) devel_moodle: not-affected (1.9.9.dfsg2-5)