Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 797667 (CVE-2021-32244) - <www-apps/moodle-3.10.4: XSS vulnerability (CVE-2021-32244)
Summary: <www-apps/moodle-3.10.4: XSS vulnerability (CVE-2021-32244)
Status: RESOLVED FIXED
Alias: CVE-2021-32244
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2021-06-22 23:18 UTC by John Helmert III
Modified: 2021-08-08 20:12 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-06-22 23:18:27 UTC
CVE-2021-32244 (https://github.com/langkexiansheng/Images/blob/master/moodle_xss.gif):

Cross Site Scripting (XSS) in Moodle 3.10.3 allows remote attackers to execute arbitrary web script or HTML via the "Description" field.

Maintainers, is this vulnerability fixed? If so, what versions are fixed?
Comment 1 Anthony Basile gentoo-dev 2021-06-24 21:15:15 UTC
I've bumped to 3.10.4 which is fixed.
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-06-25 01:09:22 UTC
Thanks! Please cleanup <3.10.4
Comment 3 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-07-25 20:29:06 UTC
Ping.
Comment 4 NATTkA bot gentoo-dev 2021-07-29 17:21:33 UTC Comment hidden (obsolete)
Comment 5 NATTkA bot gentoo-dev 2021-07-29 17:29:41 UTC Comment hidden (obsolete)
Comment 6 NATTkA bot gentoo-dev 2021-07-29 17:37:40 UTC Comment hidden (obsolete)
Comment 7 NATTkA bot gentoo-dev 2021-07-29 17:45:45 UTC Comment hidden (obsolete)
Comment 8 NATTkA bot gentoo-dev 2021-07-29 17:53:49 UTC Comment hidden (obsolete)
Comment 9 NATTkA bot gentoo-dev 2021-07-29 18:01:43 UTC Comment hidden (obsolete)
Comment 10 NATTkA bot gentoo-dev 2021-07-29 18:10:04 UTC
Package list is empty or all packages have requested keywords.
Comment 11 Anthony Basile gentoo-dev 2021-07-29 19:23:22 UTC
(In reply to John Helmert III from comment #3)
> Ping.

Sorry that was cleaned up a while ago even though I didn't respond here.
Comment 12 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-08-05 22:31:50 UTC
(In reply to Anthony Basile from comment #11)
> (In reply to John Helmert III from comment #3)
> > Ping.
> 
> Sorry that was cleaned up a while ago even though I didn't respond here.

What about 3.9.x?
Comment 13 Anthony Basile gentoo-dev 2021-08-08 20:03:53 UTC
(In reply to John Helmert III from comment #12)
> (In reply to Anthony Basile from comment #11)
> > (In reply to John Helmert III from comment #3)
> > > Ping.
> > 
> > Sorry that was cleaned up a while ago even though I didn't respond here.
> 
> What about 3.9.x?

Three branches of moodle are supported (with security).  As of today, all three version of moodle on the tree are up to day: 3.9.9, 3.10.6, 3.11.2.
Comment 14 Anthony Basile gentoo-dev 2021-08-08 20:06:31 UTC
(In reply to Anthony Basile from comment #13)
> (In reply to John Helmert III from comment #12)
> > (In reply to Anthony Basile from comment #11)
> > > (In reply to John Helmert III from comment #3)
> > > > Ping.
> > > 
> > > Sorry that was cleaned up a while ago even though I didn't respond here.
> > 
> > What about 3.9.x?
> 
> Three branches of moodle are supported (with security).  As of today, all
> three version of moodle on the tree are up to day: 3.9.9, 3.10.6, 3.11.2.

I see, maybe you're confused because 3.9.9  < 3.10.4.  Not really.  3.9.9 has the security fix cited in this bug.
Comment 15 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-08-08 20:12:15 UTC
(In reply to Anthony Basile from comment #14)
> (In reply to Anthony Basile from comment #13)
> > (In reply to John Helmert III from comment #12)
> > > (In reply to Anthony Basile from comment #11)
> > > > (In reply to John Helmert III from comment #3)
> > > > > Ping.
> > > > 
> > > > Sorry that was cleaned up a while ago even though I didn't respond here.
> > > 
> > > What about 3.9.x?
> > 
> > Three branches of moodle are supported (with security).  As of today, all
> > three version of moodle on the tree are up to day: 3.9.9, 3.10.6, 3.11.2.
> 
> I see, maybe you're confused because 3.9.9  < 3.10.4.  Not really.  3.9.9
> has the security fix cited in this bug.

Yeah, that was it. Works for me, thanks! All unstable so no GLSA. All done.