Vulnerability Name: | CVE-2020-9386 (CCN-177383) | ||||||||||||
Assigned: | 2020-03-04 | ||||||||||||
Published: | 2020-03-04 | ||||||||||||
Updated: | 2022-10-07 | ||||||||||||
Summary: | In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to group members in the Elasticsearch result list despite them not having access to that artefact anymore. | ||||||||||||
CVSS v3 Severity: | 4.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) 3.8 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-9386 Source: MISC Type: Issue Tracking, Patch, Third Party Advisory https://bugs.launchpad.net/mahara/+bug/1840201 Source: XF Type: UNKNOWN mahara-cve20209386-info-disc(177383) Source: CCN Type: Mahara Web site Home - Mahara ePortfolio System Source: CCN Type: Mahara Web site Security issue relating to incorrect access control in Elasticsearch results <18.10.5, <19.04.4, <19.10.2 Source: CONFIRM Type: Vendor Advisory https://mahara.org/interaction/forum/topic.php?id=8589 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |