{"id":"CVE-2023-35133","aliases":["BIT-moodle-2023-35133","GHSA-xxp4-mf4h-6cwm"],"url":"https://o3.security/vulnerability/CVE-2023-35133","summary":"Moodle: ssrf risk due to insufficient check on the curl blocked hosts","details":"An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.","published":"2023-06-22T00:00:00Z","modified":"2026-07-15T02:08:45.742357307Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"moodle/moodle","fixedVersion":"4.2.1"},{"ecosystem":"Packagist","name":"moodle/moodle","fixedVersion":"4.1.4"},{"ecosystem":"Packagist","name":"moodle/moodle","fixedVersion":"4.0.9"},{"ecosystem":"Packagist","name":"moodle/moodle","fixedVersion":"3.11.15"},{"ecosystem":"Packagist","name":"moodle/moodle","fixedVersion":"3.9.22"}],"fix":null,"references":[{"type":"WEB","url":"https://git.moodle.org"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=447831"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/35xxx/CVE-2023-35133.json"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7A72KX4WU6GK2CX4TKYFGFASPKOEOJFC/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I5QAEAGJ44NVXLAJFJXKARKC45OGEDXT/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-35133"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2214373"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T02:08:45.742357307Z"}}