{"id":2538,"date":"2021-01-29T08:36:32","date_gmt":"2021-01-29T13:36:32","guid":{"rendered":"https:\/\/cert.pa\/?p=2538"},"modified":"2021-01-29T08:36:32","modified_gmt":"2021-01-29T13:36:32","slug":"csirt-panama-aviso-2021-28-01-moodle-multiples-vulnerabilidades-en-moodle","status":"publish","type":"post","link":"https:\/\/cert.pa\/?p=2538","title":{"rendered":"CSIRT Panam\u00e1 Aviso 2021-28-01 Moodle: M\u00faltiples vulnerabilidades en Moodle."},"content":{"rendered":"\n<p>CSIRT Panam\u00e1 Aviso 2021-28-01 Moodle: M\u00faltiples\nvulnerabilidades en Moodle.<\/p>\n\n\n\n<p>Gravedad: Alta&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>Fecha de publicaci\u00f3n: Enero 28,\n2021<br>\n\u00daltima revisi\u00f3n: Enero 28, 2021<br>\nPortal: https:\/\/moodle.org\/<\/p>\n\n\n\n<p>Sistemas Afectados: Vulnerabilidades de severidad\ncr\u00edtica y severidad baja que afectan a los sistemas Moodle.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li><strong>Descripci\u00f3n<\/strong><\/li><\/ol>\n\n\n\n<p>Se han publicado 5 vulnerabilidades en\nMoodle, 3 de severidad cr\u00edtica y 2 de severidad baja, que podr\u00edan permitir\nataques de tipo XSS, la ejecuci\u00f3n arbitraria de c\u00f3digo PHP, la divulgaci\u00f3n de\ninformaci\u00f3n o la denegaci\u00f3n de servicio en el lado del cliente.<\/p>\n\n\n\n<p>Los recursos afectados de la versi\u00f3n\n3.10 son: <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Desde\nla versi\u00f3n 3.9, hasta la 3.9.3;<\/li><li>Desde\nla versi\u00f3n 3.8, hasta la 3.8.6;<\/li><li>Desde\nla versi\u00f3n 3.5, hasta la 3.5.15 y las versiones anteriores sin soporte.<\/li><\/ul>\n\n\n\n<ol class=\"wp-block-list\"><li><strong>Impacto<\/strong><\/li><\/ol>\n\n\n\n<p>Vulnerabilidad: CVE-2021-20183 <\/p>\n\n\n\n<p>La validaci\u00f3n insuficiente de las consultas de\nb\u00fasqueda, desde la plantilla de b\u00fasqueda de entradas, podr\u00eda permitir a un\natacante llevar a cabo ataques XSS reflejados. <\/p>\n\n\n\n<p>Vulnerabilidad: CVE-2021-20186<\/p>\n\n\n\n<p>El saneado insuficiente del contenido TeX, cuando\nel filtro de notaci\u00f3n TeX est\u00e1 activado, podr\u00eda permitir a un atacante llevar a\ncabo ataques del tipo XSS almacenado. <\/p>\n\n\n\n<p>Vulnerabilidad: CVE-2021-20187<\/p>\n\n\n\n<p>Los administradores del sitio podr\u00edan ejecutar\nscripts PHP arbitrarios a trav\u00e9s de un include PHP, utilizado durante la\nautenticaci\u00f3n de Shibboleth. <\/p>\n\n\n\n<p>Las vulnerabilidades de severidad baja, se han\nasignado los identificadores CVE-2021-20184 y CVE-2021-20185.<\/p>\n\n\n\n<p><strong>III. Referencia a soluciones, herramientas e\ninformaci\u00f3n<\/strong><strong><\/strong><\/p>\n\n\n\n<p>Actualizaci\u00f3n de los recursos Moodle a las\nversiones <a href=\"https:\/\/docs.moodle.org\/dev\/Moodle_3.10.1_release_notes\">3.10.1<\/a>;\n<a href=\"https:\/\/docs.moodle.org\/dev\/Moodle_3.9.4_release_notes\">3.9.4<\/a>;\n<a href=\"https:\/\/docs.moodle.org\/dev\/Moodle_3.8.7_release_notes\">3.8.7<\/a>;\n<a href=\"https:\/\/docs.moodle.org\/dev\/Moodle_3.5.16_release_notes\">3.5.16<\/a>.<\/p>\n\n\n\n<p>Puede realizar estas descargas desde su sitio\noficial <a href=\"https:\/\/download.moodle.org\/\">https:\/\/download.moodle.org\/<\/a>. <\/p>\n\n\n\n<p><strong>Fuentes:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Moodle\n3.10.1 and other minor versions released!. 18 de enero del 2021. Recopilado en:\nhttps:\/\/moodle.org\/news\/<\/li><li>INCIBE.\nInstituto Nacional de Ciberseguridad. Espa\u00f1a. M\u00faltiples vulnerabilidades en\nMoodle. 25 de enero del 2021. Avisos de seguridad. Recopilado en: https:\/\/www.incibe-cert.es\/alerta-temprana\/avisos-seguridad\/multiples-vulnerabilidades-moodle-12<\/li><\/ul>\n\n\n\n<p><strong>Informaci\u00f3n de contacto<\/strong><br>\nCSIRT PANAMA<br>\nComputer Security Incident Response Team Autoridad Nacional para la Innovacion\nGubernamental<br>\nE-Mail: info@cert.pa<br>\nPhone: +507 520-CERT (2378)<br>\nWeb: https:\/\/cert.pa<br>\nTwitter: @CSIRTPanama<br>\nKey ID: 16F2B124<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CSIRT Panam\u00e1 Aviso 2021-28-01 Moodle: M\u00faltiples vulnerabilidades en Moodle. Gravedad: Alta&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Fecha de publicaci\u00f3n: Enero 28, 2021 \u00daltima revisi\u00f3n: Enero 28, 2021 Portal: https:\/\/moodle.org\/ Sistemas Afectados: Vulnerabilidades de severidad cr\u00edtica y severidad baja que afectan&#8230;<\/p>\n","protected":false},"author":4,"featured_media":2299,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[4],"tags":[],"class_list":["post-2538","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-avisos-de-seguridad"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/2538","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2538"}],"version-history":[{"count":1,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/2538\/revisions"}],"predecessor-version":[{"id":2539,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/2538\/revisions\/2539"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/media\/2299"}],"wp:attachment":[{"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2538"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2538"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2538"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}