To address a cache poisoning risk in Moodle, additional validation for local storage was required.
Workaround:
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2304256 | issue tracking permissions required |
https://moodle.org/mod/forum/discuss.php?d=461196 | vendor advisory |