Fedora Linux 8568 Published by

A moodle security update has been released for Fedora 36.



SECURITY: Fedora 36 Update: moodle-3.11.13-1.fc36


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2023-d9c13996b2
2023-03-30 01:14:14.931163
--------------------------------------------------------------------------------

Name : moodle
Product : Fedora 36
Version : 3.11.13
Release : 1.fc36
URL :   http://moodle.org/
Summary : A Course Management System
Description :
Moodle is a course management system (CMS) - a free, Open Source software
package designed using sound pedagogical principles, to help educators create
effective online learning communities.

--------------------------------------------------------------------------------
Update Information:

Fixes for multiple CVEs.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Mar 21 2023 Gwyn Ciesla - 3.11.13-1
- 3.11.13
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2180072 - CVE-2023-28329 moodle: Authenticated SQL injection via availability check [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=2180072
[ 2 ] Bug #2180078 - CVE-2023-28330 moodle: Authenticated arbitrary file read through malformed backup file [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=2180078
[ 3 ] Bug #2180080 - CVE-2023-28331 moodle: XSS risk when outputting database activity filter data [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=2180080
[ 4 ] Bug #2180082 - CVE-2023-28332 moodle: Algebra filter XSS when filter is misconfigured [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=2180082
[ 5 ] Bug #2180084 - CVE-2023-28333 moodle: Pix helper potential Mustache code injection risk [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=2180084
[ 6 ] Bug #2180092 - CVE-2023-28336 moodle: Teacher can access names of users they do not have permission to access [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=2180092
[ 7 ] Bug #2180098 - CVE-2023-1402 moodle: Course participation report shows roles the user should not see [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=2180098
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2023-d9c13996b2' at the command
line. For more information, refer to the dnf documentation available at
  http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
  https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________