Description
An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.
Remediation
References
Related Vulnerabilities
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2020-9547)
OpenSSL Uncontrolled Resource Consumption Vulnerability (CVE-2016-8610)
Oracle Database Server CVE-2011-0838 Vulnerability (CVE-2011-0838)
YOURLS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3824)
WordPress Plugin Abandoned Cart Lite for WooCommerce SQL Injection (1.8)