MSA-13-0018: Personal information leak through repositories

MSA-13-0018: Personal information leak through repositories

by Michael de Raadt -
Number of replies: 0
Description: Users able to use "login as" were able to see the personal repository content of the user they were impersonating
Issue summary: Admin users logged in as another user have access to the content of their external repositories
Severity/Risk: Serious
Versions affected: 2.4 to 2.4.1, 2.3 to 2.3.4, 2.2 to 2.2.7, earlier unsupported versions (2.x only)
Versions fixed: 2.4.2 and 2.4.3, 2.3.5 and 2.3.6, 2.2.8 and 2.2.9
Reported by: Andrew Nicols
Issue no.: MDL-36426
CVE identifier: CVE-2013-1835
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-36426