The web service responsible for fetching other users’ enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
bugzilla.redhat.com/show_bug.cgi?id=1939051
github.com/moodle/moodle
lists.fedoraproject.org/archives/list/[email protected]/message/AFSNJ7XHVTC52RSRX2GBQFF3VEEAY2MS
lists.fedoraproject.org/archives/list/[email protected]/message/UFH5DDMU5TZ3JT4Q52WMRAHACA5MHIMT
moodle.org/mod/forum/discuss.php?d=419654
nvd.nist.gov/vuln/detail/CVE-2021-20283