« Volver al listado

CVE-2024-43433

Estado: AnalizadaMedia (5.3)—

A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-43433",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-43433",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-11-12T15:02:57.899042Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "patrick@puiterwijk.org",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "patrick@puiterwijk.org",
      "affectedData": [
        {
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "4.1.12",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.2",
              "lessThan": "4.2.9",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.3",
              "lessThan": "4.3.6",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.4",
              "lessThan": "4.4.2",
              "versionType": "semver"
            }
          ],
          "packageName": "moodle",
          "collectionURL": "https://github.com/moodle/moodle",
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*"
          ],
          "vendor": "moodle",
          "product": "moodle",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "4.1.12",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.2",
              "lessThan": "4.2.9",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.3",
              "lessThan": "4.3.6",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.4",
              "lessThan": "4.4.2",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-11-11T13:15:04.410",
  "references": [
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2304261",
      "tags": [
        "Permissions Required"
      ],
      "source": "patrick@puiterwijk.org"
    },
    {
      "url": "https://moodle.org/mod/forum/discuss.php?d=461202",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "patrick@puiterwijk.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users."
    },
    {
      "lang": "es",
      "value": "Se encontró una falla en Moodle. La membresía de la sala Matrix y los niveles de poder se aplican y revocan incorrectamente para los usuarios suspendidos de Moodle."
    }
  ],
  "lastModified": "2026-06-17T07:51:02.240",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FBA8C381-9493-42BD-A5EA-7AADFAB68C5E",
              "versionEndExcluding": "4.3.6",
              "versionStartIncluding": "4.3.0"
            },
            {
              "criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "277E1058-2F00-45DB-8BFC-2628CCC89981",
              "versionEndExcluding": "4.4.2",
              "versionStartIncluding": "4.4.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "patrick@puiterwijk.org"
}