Moodle Improper Authentication
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Apr 23, 2024
Package
Affected versions
>= 3.3, < 3.3.5
>= 3.4, < 3.4.2
Patched versions
3.3.5
3.4.2
Description
Published by the National Vulnerability Database
Apr 4, 2018
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Apr 23, 2024
Reviewed
Apr 23, 2024
A flaw was found in Moodle 3.4 to 3.4.1, and 3.3 to 3.3.4. If a user account using OAuth2 authentication method was once confirmed but later suspended, the user could still login to the site.
References