Vulnerability Name: | CVE-2014-0008 (CCN-90577) | ||||||||||||||||||||
Assigned: | 2013-12-03 | ||||||||||||||||||||
Published: | 2014-01-20 | ||||||||||||||||||||
Updated: | 2020-12-01 | ||||||||||||||||||||
Summary: | lib/adminlib.php in Moodle through 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 logs cleartext passwords, which allows remote authenticated administrators to obtain sensitive information by reading the Config Changes Report. | ||||||||||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-255 | ||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2014-0008 Source: CONFIRM Type: Patch http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-36721 Source: FEDORA Type: UNKNOWN FEDORA-2014-1377 Source: FEDORA Type: UNKNOWN FEDORA-2014-1396 Source: MLIST Type: UNKNOWN [oss-security] 20140120 Moodle security notifications public Source: CCN Type: oss-security: Mon, 20 Jan 2014 Moodle security notifications public Source: CCN Type: BID-65026 Moodle Config Changes Report Password Disclosure Vulnerability Source: SECTRACK Type: UNKNOWN 1029647 Source: XF Type: UNKNOWN moodle-cve20140008-info-disclosure(90577) Source: CCN Type: Moodle Web site Moodle.org: open-source community-based tools for learning Source: CCN Type: MSA-14-0001 Config passwords visibility issue Source: CONFIRM Type: Patch, Vendor Advisory https://moodle.org/mod/forum/discuss.php?d=252414 Source: CCN Type: WhiteSource Vulnerability Database CVE-2014-0008 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration 4: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |