Authenticated users were able to enumerate other users' names via the learning plans page.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2179423 | issue tracking |
https://moodle.org/mod/forum/discuss.php?d=445066 | patch vendor advisory |