GHSA-7wmp-2xmx-g6h8
GitHub Security Advisory
Moodle authorization headers preserved between "emulated redirects"
✓ GitHub Reviewed
LOW
Has CVE
Advisory Details
A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
Affected Packages
Packagist
moodle/moodle
Affected versions:
4.4.0
(fixed in 4.4.2)
Packagist
moodle/moodle
Affected versions:
4.3.0
(fixed in 4.3.6)
Packagist
moodle/moodle
Affected versions:
4.2.0
(fixed in 4.2.9)
Packagist
moodle/moodle
Affected versions:
0
(fixed in 4.1.12)
Related CVEs
Key Information
2.5
/10
Dataset
Last updated: September 15, 2025 6:32 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.