PT-2023-32169 · Moodle+7 · Moodle+6

Yaniv Nizry

·

Published

2023-11-09

·

Updated

2024-03-06

·

CVE-2023-5548

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue involves the need for stronger revision number limitations on file serving endpoints to enhance cache poisoning protection. This is a measure to improve security against potential cache poisoning attacks, which could compromise the integrity of cached data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

BIT-MOODLE-2023-5548
CVE-2023-5548
GHSA-CWH2-Q44X-5W3C

Affected Products

Moodle
Ckeditor4
Extra Packages For Enterprise Linux
Fedora
Moodle/Moodle
Upx
Wireshark