Unintentionally Sending HTTP Authorization Header Information Through Redirects
CVE-2024-38275
Currently unrated
What is CVE-2024-38275?
The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Moodle 4.4
Moodle 4.3 <= 4.3.4
Moodle 4.2 <= 4.2.7