Show plain JSON{"id": "CVE-2019-14830", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.8, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 4.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "CHANGED", "version": "3.1", "baseScore": 6.1, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "integrityImpact": "LOW", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "LOW"}, "impactScore": 2.7, "exploitabilityScore": 2.8}]}, "published": "2021-03-19T21:15:12.040", "references": [{"url": "https://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=d4985a77391123c5959db432c076328f8d5e3624", "source": "secalert@redhat.com"}, {"url": "https://moodle.org/mod/forum/discuss.php?d=391036", "tags": ["Release Notes", "Vendor Advisory"], "source": "secalert@redhat.com"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "secalert@redhat.com", "description": [{"lang": "en", "value": "CWE-601"}]}], "descriptions": [{"lang": "en", "value": "A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where the mobile launch endpoint contained an open redirect in some circumstances, which could result in a user's mobile access token being exposed. (Note: This does not affect sites with a forced URL scheme configured, mobile service disabled, or where the mobile app login method is \"via the app\")."}, {"lang": "es", "value": "Se encontr\u00f3 una vulnerabilidad en Moodle versiones 3.7 hasta 3.7.1, versiones 3.6 hasta 3.6.5, versiones 3.5 hasta 3.5.7 y versiones anteriores no compatibles, donde el endpoint de lanzamiento m\u00f3vil conten\u00eda un redireccionamiento abierto en algunas circunstancias, lo que podr\u00eda resultar en un token de acceso m\u00f3vil de un usuario sea expuesto. (Nota: esto no afecta a sitios con un esquema de URL forzado configurado, servicio m\u00f3vil desactivado o donde el m\u00e9todo de inicio de sesi\u00f3n de la aplicaci\u00f3n m\u00f3vil es \"via the app\")"}], "lastModified": "2023-02-12T23:34:48.050", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4D443C9B-4E6C-4DFC-BC79-249FE71A44CB", "versionEndIncluding": "3.5.7", "versionStartIncluding": "3.5.0"}, {"criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "850D661D-990A-4A27-864B-1F52DD5F94D8", "versionEndIncluding": "3.6.5", "versionStartIncluding": "3.6.0"}, {"criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E2879DC1-468C-4692-9D43-23DAFB088145", "versionEndIncluding": "3.7.1", "versionStartIncluding": "3.7.0"}], "operator": "OR"}]}], "sourceIdentifier": "secalert@redhat.com"}