# CVE-2024-38277

## Summary

- **CVE ID:** CVE-2024-38277
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** CWE-324
- **Published:** Jun 18, 2024
- **Last Modified:** Mar 13, 2026

## Description

A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.

## Affected Products

- Moodle — Moodle (4.4)
- Moodle — Moodle (4.3)
- Moodle — Moodle (4.2)
- Moodle — Moodle (4.1)

## References

- [CNA](https://moodle.org/mod/forum/discuss.php?d=459502)
- [CNA](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GHTIX55J4Q4LEOMLNEA4OZSWVEENQX7E/)
- [CNA](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F7AZYR7EXV6E5SQE2GYTNQE3NOENJCQ6/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.24%
- **EPSS Percentile:** 15.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._