MSA-12-0040: Capabilities issue through caching

MSA-12-0040: Capabilities issue through caching

by Michael de Raadt -
Number of replies: 0
Topic: lib/accesslib.php is_enrolled doesn't check capabilities for cached users
Severity/Risk: Minor
Versions affected: 2.3, 2.2 to 2.2.3+
Reported by: Andrew Nicols
Issue no.: MDL-33916

CVE Identifier:

CVE-2012-3388
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-33916

Description:

Capability checks were not working properly after a user record had been cached.