Vulnerability Name:

CVE-2014-0129 (CCN-91962)

Assigned:2013-12-03
Published:2014-03-17
Updated:2020-12-01
Summary:badges/mybadges.php in Moodle 2.5.x before 2.5.5 and 2.6.x before 2.6.2 does not properly track the user to whom a badge was issued, which allows remote authenticated users to modify the visibility of an arbitrary badge via unspecified vectors.
CVSS v3 Severity:2.6 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N)
3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
3.5 Low (CCN CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N)
2.6 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-264
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2014-0129

Source: CONFIRM
Type: UNKNOWN
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-44140

Source: MLIST
Type: UNKNOWN
[oss-security] 20140317 Moodle security notifications public

Source: CCN
Type: SA57331
Moodle Multiple Security Issues and Multiple Vulnerabilities

Source: CCN
Type: SA57338
Moodle Multiple Security Issues and Multiple Vulnerabilities

Source: CCN
Type: BID-66337
Moodle Badges Access Bypass Vulnerability

Source: XF
Type: UNKNOWN
moodle-cve20140129-sec-bypass(91962)

Source: CCN
Type: MSA-14-0012
Access issue in Badges

Source: CONFIRM
Type: Vendor Advisory
https://moodle.org/mod/forum/discuss.php?d=256424

Source: CCN
Type: Moodle Security Announcements
Security Announcements

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2014-0129

Vulnerable Configuration:Configuration 1:
  • cpe:/a:moodle:moodle:2.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.1.9:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.2.4:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.2.6:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.4.5:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.4.7:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:*:*:*:*:*:*:*:* (Version <= 2.3.11)
  • OR cpe:/a:moodle:moodle:2.3.3:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.1.5:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.1.6:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.1.7:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.2.8:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.2.9:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.6.0:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.6.1:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.4.8:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.3.10:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.0.6:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.0.7:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.0.8:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.0.9:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.2.10:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.2.11:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.4.1:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.4.2:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.4.3:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.3.5:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.3.6:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.3.7:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.3.8:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.1.10:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.1.8:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.2.5:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.2.7:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.5.4:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.4.4:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.4.6:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.3.2:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.3.4:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.3.9:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:moodle:moodle:2.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.6.0:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:2.6.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:com.ubuntu.bionic:def:201401290000000
    V
    CVE-2014-0129 on Ubuntu 18.04 LTS (bionic) - low.
    2014-03-24
    oval:com.ubuntu.artful:def:20140129000
    V
    CVE-2014-0129 on Ubuntu 17.10 (artful) - low.
    2014-03-24
    oval:com.ubuntu.trusty:def:20140129000
    V
    CVE-2014-0129 on Ubuntu 14.04 LTS (trusty) - low.
    2014-03-24
    oval:com.ubuntu.xenial:def:201401290000000
    V
    CVE-2014-0129 on Ubuntu 16.04 LTS (xenial) - low.
    2014-03-24
    oval:com.ubuntu.bionic:def:20140129000
    V
    CVE-2014-0129 on Ubuntu 18.04 LTS (bionic) - low.
    2014-03-24
    oval:com.ubuntu.xenial:def:20140129000
    V
    CVE-2014-0129 on Ubuntu 16.04 LTS (xenial) - low.
    2014-03-24
    oval:com.ubuntu.disco:def:201401290000000
    V
    CVE-2014-0129 on Ubuntu 19.04 (disco) - low.
    2014-03-24
    oval:com.ubuntu.cosmic:def:20140129000
    V
    CVE-2014-0129 on Ubuntu 18.10 (cosmic) - low.
    2014-03-24
    oval:com.ubuntu.cosmic:def:201401290000000
    V
    CVE-2014-0129 on Ubuntu 18.10 (cosmic) - low.
    2014-03-24
    oval:com.ubuntu.precise:def:20140129000
    V
    CVE-2014-0129 on Ubuntu 12.04 LTS (precise) - low.
    2014-03-24
    BACK
    moodle moodle 2.0.2
    moodle moodle 2.0.4
    moodle moodle 2.1.1
    moodle moodle 2.1.2
    moodle moodle 2.1.9
    moodle moodle 2.2.1
    moodle moodle 2.2.4
    moodle moodle 2.2.6
    moodle moodle 2.5.1
    moodle moodle 2.5.3
    moodle moodle 2.4.5
    moodle moodle 2.4.7
    moodle moodle *
    moodle moodle 2.3.3
    moodle moodle 2.0.0
    moodle moodle 2.0.1
    moodle moodle 2.1.4
    moodle moodle 2.1.5
    moodle moodle 2.1.6
    moodle moodle 2.1.7
    moodle moodle 2.2.8
    moodle moodle 2.2.9
    moodle moodle 2.6.0
    moodle moodle 2.6.1
    moodle moodle 2.4.8
    moodle moodle 2.3.0
    moodle moodle 2.3.1
    moodle moodle 2.3.10
    moodle moodle 2.0.6
    moodle moodle 2.0.7
    moodle moodle 2.0.8
    moodle moodle 2.0.9
    moodle moodle 2.2.10
    moodle moodle 2.2.11
    moodle moodle 2.2.2
    moodle moodle 2.2.3
    moodle moodle 2.4.0
    moodle moodle 2.4.1
    moodle moodle 2.4.2
    moodle moodle 2.4.3
    moodle moodle 2.3.5
    moodle moodle 2.3.6
    moodle moodle 2.3.7
    moodle moodle 2.3.8
    moodle moodle 2.0.3
    moodle moodle 2.0.5
    moodle moodle 2.1.0
    moodle moodle 2.1.10
    moodle moodle 2.1.3
    moodle moodle 2.1.8
    moodle moodle 2.2.0
    moodle moodle 2.2.5
    moodle moodle 2.2.7
    moodle moodle 2.5.0
    moodle moodle 2.5.2
    moodle moodle 2.5.4
    moodle moodle 2.4.4
    moodle moodle 2.4.6
    moodle moodle 2.3.2
    moodle moodle 2.3.4
    moodle moodle 2.3.9
    moodle moodle 2.4.0
    moodle moodle 2.5.0
    moodle moodle 2.6.0
    moodle moodle 2.6.1