MSA-15-0038: DDoS possibility in Atto

MSA-15-0038: DDoS possibility in Atto

by Marina Glancy -
Number of replies: 0
Description: If guest access is open on the site, unauthenticated user can create a DDos attack through editor autosave area
Issue summary: Guests can exploit atto draft to store content
Severity/Risk: Serious
Versions affected: 2.9 to 2.9.2 and 2.8 to 2.8.8
Versions fixed: 2.9.3 and 2.8.9
Reported by: Frédéric Massart
Issue no.: MDL-51000
Workaround: Disable guest access until the fix is applied
CVE identifier: CVE-2015-5332
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-51000