CVE-2024-38277

MEDIUM

Unknown - Info Disclosure

Title source: llm

Description

A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.

Scores

CVSS v3 5.4
EPSS 0.0019
EPSS Percentile 40.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Classification

CWE
CWE-326 CWE-324
Status published

Affected Products (5)

moodle/moodle < 4.1.11
moodle/moodle
fedoraproject/fedora
fedoraproject/fedora
moodle/moodle < 4.4.1Packagist

Timeline

Published Jun 18, 2024
Tracked Since Feb 18, 2026