CVE-2024-34009
moodle: ReCAPTCHA can be bypassed on the login page
7.5
HIGH
CVSS 3.1
EPSS 0.14%
Description
Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCAPTCHA is utilized.
How to fix CVE-2024-34009
To remediate CVE-2024-34009, upgrade the affected package to a fixed version below.
- Bitnami/moodle—upgrade to 4.3.4 or later
- —upgrade to 4.3.4 or later
Is CVE-2024-34009 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 4.3.0, < 4.3.4
- >= 4.3.0, < 4.3.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |