HomeDefault status
unaffected
4.1.0 (semver) before 4.1.2
affected
4.0.0 (semver) before 4.0.7
affected
Description
Authenticated users were able to enumerate other users' names via the learning plans page.
Problem types
Exposure of Sensitive Information to an Unauthorized Actor
Product status
4.1.0 (semver) before 4.1.2
4.0.0 (semver) before 4.0.7
Timeline
| 2023-03-10: | Reported to Red Hat. |
| 2023-03-20: | Made public. |
References
bugzilla.redhat.com/show_bug.cgi?id=2179423 (RHBZ#2179423)
moodle.org/mod/forum/discuss.php?d=445066
bugzilla.redhat.com/show_bug.cgi?id=2179423 (RHBZ#2179423)
moodle.org/mod/forum/discuss.php?d=445066