mod/forum/user.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 allows remote authenticated users to discover the names of other users via unspecified vectors.
https://bugzilla.redhat.com/show_bug.cgi?id=747444
http://www.debian.org/security/2012/dsa-2421