MSA-12-0046: Insecure protocol redirection in LDAP authentication

MSA-12-0046: Insecure protocol redirection in LDAP authentication

by Michael de Raadt -
Number of replies: 0
Topic: redirect() "forgets" https
Severity/Risk: Minor
Versions affected: 2.3, 2.2 to 2.2.3+, 2.1 to 2.1.6+, 2.0 to 2.0.9+
Reported by: Christophe
Issue no.: MDL-23254

CVE Identifier:

CVE-2012-3394
Changes (2.2): http://git.moodle.org/gw?p=moodle.git;a=commit;h=9d8d2ee6192e8b7ebb6713bd6215e06f94e2a9f7

Description:

Users redirected during a login utilising LDAP were being redirected from https to http protocol.