You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: general/releases/4.1/4.1.19.md
+9-2Lines changed: 9 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -18,5 +18,12 @@ import { ReleaseNoteIntro } from '@site/src/components/ReleaseInformation';
18
18
<!-- cspell:enable -->
19
19
20
20
## Security fixes
21
-
22
-
A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version.
21
+
<!-- cspell:disable -->
22
+
-[MSA-25-0030](https://moodle.org/mod/forum/discuss.php?d=468501) - Password can be revealed in login page after log out due to caching
23
+
-[MSA-25-0031](https://moodle.org/mod/forum/discuss.php?d=468502) - Upgrade ADOdb including security fix (upstream)
24
+
-[MSA-25-0032](https://moodle.org/mod/forum/discuss.php?d=468503) - SSRF risk via DNS rebind
25
+
-[MSA-25-0033](https://moodle.org/mod/forum/discuss.php?d=468504) - Course visibility not honoured consistently
26
+
-[MSA-25-0034](https://moodle.org/mod/forum/discuss.php?d=468505) - CSRF risk in badges backpack management
27
+
-[MSA-25-0035](https://moodle.org/mod/forum/discuss.php?d=468506) - Missing authorisation checks in BigBlueButton view page
28
+
-[MSA-25-0036](https://moodle.org/mod/forum/discuss.php?d=468507) - IDOR allows fetching of recently accessed courses for other users via web service
Copy file name to clipboardExpand all lines: general/releases/4.4/4.4.9.md
+9-2Lines changed: 9 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -39,5 +39,12 @@ import { ReleaseNoteIntro } from '@site/src/components/ReleaseInformation';
39
39
<!-- cspell:enable -->
40
40
41
41
## Security fixes
42
-
43
-
A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version.
42
+
<!-- cspell:disable -->
43
+
-[MSA-25-0030](https://moodle.org/mod/forum/discuss.php?d=468501) - Password can be revealed in login page after log out due to caching
44
+
-[MSA-25-0031](https://moodle.org/mod/forum/discuss.php?d=468502) - Upgrade ADOdb including security fix (upstream)
45
+
-[MSA-25-0032](https://moodle.org/mod/forum/discuss.php?d=468503) - SSRF risk via DNS rebind
46
+
-[MSA-25-0033](https://moodle.org/mod/forum/discuss.php?d=468504) - Course visibility not honoured consistently
47
+
-[MSA-25-0034](https://moodle.org/mod/forum/discuss.php?d=468505) - CSRF risk in badges backpack management
48
+
-[MSA-25-0035](https://moodle.org/mod/forum/discuss.php?d=468506) - Missing authorisation checks in BigBlueButton view page
49
+
-[MSA-25-0036](https://moodle.org/mod/forum/discuss.php?d=468507) - IDOR allows fetching of recently accessed courses for other users via web service
Copy file name to clipboardExpand all lines: general/releases/4.5/4.5.5.md
+9-2Lines changed: 9 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -83,5 +83,12 @@ import { ReleaseNoteIntro } from '@site/src/components/ReleaseInformation';
83
83
<!-- cspell:enable -->
84
84
85
85
## Security fixes
86
-
87
-
A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version.
86
+
<!-- cspell:disable -->
87
+
-[MSA-25-0030](https://moodle.org/mod/forum/discuss.php?d=468501) - Password can be revealed in login page after log out due to caching
88
+
-[MSA-25-0031](https://moodle.org/mod/forum/discuss.php?d=468502) - Upgrade ADOdb including security fix (upstream)
89
+
-[MSA-25-0032](https://moodle.org/mod/forum/discuss.php?d=468503) - SSRF risk via DNS rebind
90
+
-[MSA-25-0033](https://moodle.org/mod/forum/discuss.php?d=468504) - Course visibility not honoured consistently
91
+
-[MSA-25-0034](https://moodle.org/mod/forum/discuss.php?d=468505) - CSRF risk in badges backpack management
92
+
-[MSA-25-0035](https://moodle.org/mod/forum/discuss.php?d=468506) - Missing authorisation checks in BigBlueButton view page
93
+
-[MSA-25-0036](https://moodle.org/mod/forum/discuss.php?d=468507) - IDOR allows fetching of recently accessed courses for other users via web service
Copy file name to clipboardExpand all lines: general/releases/5.0/5.0.1.md
+10-2Lines changed: 10 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -92,5 +92,13 @@ import { ReleaseNoteIntro } from '@site/src/components/ReleaseInformation';
92
92
<!-- cspell:enable -->
93
93
94
94
## Security fixes
95
-
96
-
A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version.
95
+
<!-- cspell:disable -->
96
+
-[MSA-25-0029](https://moodle.org/mod/forum/discuss.php?d=468500) - XSS risk in MathJax (safe extension not loaded)
97
+
-[MSA-25-0030](https://moodle.org/mod/forum/discuss.php?d=468501) - Password can be revealed in login page after log out due to caching
98
+
-[MSA-25-0031](https://moodle.org/mod/forum/discuss.php?d=468502) - Upgrade ADOdb including security fix (upstream)
99
+
-[MSA-25-0032](https://moodle.org/mod/forum/discuss.php?d=468503) - SSRF risk via DNS rebind
100
+
-[MSA-25-0033](https://moodle.org/mod/forum/discuss.php?d=468504) - Course visibility not honoured consistently
101
+
-[MSA-25-0034](https://moodle.org/mod/forum/discuss.php?d=468505) - CSRF risk in badges backpack management
102
+
-[MSA-25-0035](https://moodle.org/mod/forum/discuss.php?d=468506) - Missing authorisation checks in BigBlueButton view page
103
+
-[MSA-25-0036](https://moodle.org/mod/forum/discuss.php?d=468507) - IDOR allows fetching of recently accessed courses for other users via web service
0 commit comments