VulnerabilityModified
CVE-2020-9386
In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to group members in the Elasticsearch result list despite them not having access to that artefact anymore.
MEDIUM 4.3EPSS 1.00%
Does this matter?
Lower severity and a low EPSS score (1.00%). Track it; it rarely justifies an emergency change on its own.
Description
In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to group members in the Elasticsearch result list despite them not having access to that artefact anymore.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.00% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- mahara/mahara
- Source
- cve@mitre.org
References
- https://bugs.launchpad.net/mahara/+bug/1840201Issue Tracking, Patch, Third Party Advisory
- https://mahara.org/interaction/forum/topic.php?id=8589Vendor Advisory
- https://bugs.launchpad.net/mahara/+bug/1840201Issue Tracking, Patch, Third Party Advisory
- https://mahara.org/interaction/forum/topic.php?id=8589Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.