CVE-2024-38277
18.06.2024, 20:15
A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.Enginsight
Vendor | Product | Version |
---|---|---|
moodle | moodle | 4.1.0 ≤ 𝑥 < 4.1.11 |
moodle | moodle | 4.2.0 ≤ 𝑥 < 4.2.8 |
moodle | moodle | 4.3.0 ≤ 𝑥 < 4.3.5 |
moodle | moodle | 4.4.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
- CWE-324 - Use of a Key Past its Expiration DateThe product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.
- CWE-326 - Inadequate Encryption StrengthThe software stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
References