Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 797667 (CVE-2021-32244)

Summary: <www-apps/moodle-3.10.4: XSS vulnerability (CVE-2021-32244)
Product: Gentoo Security Reporter: John Helmert III <ajak>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: trivial CC: blueness, web-apps
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: ~3 [noglsa]
Package list:
Runtime testing required: ---

Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-06-22 23:18:27 UTC
CVE-2021-32244 (https://github.com/langkexiansheng/Images/blob/master/moodle_xss.gif):

Cross Site Scripting (XSS) in Moodle 3.10.3 allows remote attackers to execute arbitrary web script or HTML via the "Description" field.

Maintainers, is this vulnerability fixed? If so, what versions are fixed?
Comment 1 Anthony Basile gentoo-dev 2021-06-24 21:15:15 UTC
I've bumped to 3.10.4 which is fixed.
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-06-25 01:09:22 UTC
Thanks! Please cleanup <3.10.4
Comment 3 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-07-25 20:29:06 UTC
Ping.
Comment 4 NATTkA bot gentoo-dev 2021-07-29 17:21:33 UTC Comment hidden (obsolete)
Comment 5 NATTkA bot gentoo-dev 2021-07-29 17:29:41 UTC Comment hidden (obsolete)
Comment 6 NATTkA bot gentoo-dev 2021-07-29 17:37:40 UTC Comment hidden (obsolete)
Comment 7 NATTkA bot gentoo-dev 2021-07-29 17:45:45 UTC Comment hidden (obsolete)
Comment 8 NATTkA bot gentoo-dev 2021-07-29 17:53:49 UTC Comment hidden (obsolete)
Comment 9 NATTkA bot gentoo-dev 2021-07-29 18:01:43 UTC Comment hidden (obsolete)
Comment 10 NATTkA bot gentoo-dev 2021-07-29 18:10:04 UTC
Package list is empty or all packages have requested keywords.
Comment 11 Anthony Basile gentoo-dev 2021-07-29 19:23:22 UTC
(In reply to John Helmert III from comment #3)
> Ping.

Sorry that was cleaned up a while ago even though I didn't respond here.
Comment 12 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-08-05 22:31:50 UTC
(In reply to Anthony Basile from comment #11)
> (In reply to John Helmert III from comment #3)
> > Ping.
> 
> Sorry that was cleaned up a while ago even though I didn't respond here.

What about 3.9.x?
Comment 13 Anthony Basile gentoo-dev 2021-08-08 20:03:53 UTC
(In reply to John Helmert III from comment #12)
> (In reply to Anthony Basile from comment #11)
> > (In reply to John Helmert III from comment #3)
> > > Ping.
> > 
> > Sorry that was cleaned up a while ago even though I didn't respond here.
> 
> What about 3.9.x?

Three branches of moodle are supported (with security).  As of today, all three version of moodle on the tree are up to day: 3.9.9, 3.10.6, 3.11.2.
Comment 14 Anthony Basile gentoo-dev 2021-08-08 20:06:31 UTC
(In reply to Anthony Basile from comment #13)
> (In reply to John Helmert III from comment #12)
> > (In reply to Anthony Basile from comment #11)
> > > (In reply to John Helmert III from comment #3)
> > > > Ping.
> > > 
> > > Sorry that was cleaned up a while ago even though I didn't respond here.
> > 
> > What about 3.9.x?
> 
> Three branches of moodle are supported (with security).  As of today, all
> three version of moodle on the tree are up to day: 3.9.9, 3.10.6, 3.11.2.

I see, maybe you're confused because 3.9.9  < 3.10.4.  Not really.  3.9.9 has the security fix cited in this bug.
Comment 15 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-08-08 20:12:15 UTC
(In reply to Anthony Basile from comment #14)
> (In reply to Anthony Basile from comment #13)
> > (In reply to John Helmert III from comment #12)
> > > (In reply to Anthony Basile from comment #11)
> > > > (In reply to John Helmert III from comment #3)
> > > > > Ping.
> > > > 
> > > > Sorry that was cleaned up a while ago even though I didn't respond here.
> > > 
> > > What about 3.9.x?
> > 
> > Three branches of moodle are supported (with security).  As of today, all
> > three version of moodle on the tree are up to day: 3.9.9, 3.10.6, 3.11.2.
> 
> I see, maybe you're confused because 3.9.9  < 3.10.4.  Not really.  3.9.9
> has the security fix cited in this bug.

Yeah, that was it. Works for me, thanks! All unstable so no GLSA. All done.