Note:

If you want to create a new page for developers, you should create it on the Moodle Developer Resource site.

Moodle 3.5.17 release notes: Difference between revisions

From MoodleDocs
m (released)
m (Protected "Moodle 3.5.17 release notes": Developer Docs Migration ([Edit=Allow only administrators] (indefinite)))
 
(3 intermediate revisions by 2 users not shown)
Line 1: Line 1:
{{Template:Migrated|newDocId=/general/releases/3.5/3.5.17}}
<p class="note">'''This version of Moodle is no longer supported for general bug fixes.''' You are encouraged to [[:en:Upgrading|upgrade]] to a supported version of Moodle.</p>
<p class="note">'''This version of Moodle is no longer supported for general bug fixes.''' You are encouraged to [[:en:Upgrading|upgrade]] to a supported version of Moodle.</p>


Line 7: Line 8:
Here is [https://tracker.moodle.org/secure/IssueNavigator!executeAdvanced.jspa?jqlQuery=project+%3D+mdl+AND+resolution+%3D+fixed+AND+fixVersion+in+%28%223.5.17%22%29+ORDER+BY+priority+DESC&runQuery=true&clear=true the full list of fixed issues in 3.5.17].
Here is [https://tracker.moodle.org/secure/IssueNavigator!executeAdvanced.jspa?jqlQuery=project+%3D+mdl+AND+resolution+%3D+fixed+AND+fixVersion+in+%28%223.5.17%22%29+ORDER+BY+priority+DESC&runQuery=true&clear=true the full list of fixed issues in 3.5.17].
   
   
==Security issues==
==Security fixes==
Details of any security issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version.
   
   
* [https://moodle.org/mod/forum/discuss.php?d=419650 MSA-21-0006] Stored XSS via ID number user profile field
* [https://moodle.org/mod/forum/discuss.php?d=419651 MSA-21-0007] Stored XSS and blind SSRF possible via feedback answer text
* [https://moodle.org/mod/forum/discuss.php?d=419652 MSA-21-0008] User full name disclosure within online users block
* [https://moodle.org/mod/forum/discuss.php?d=419653 MSA-21-0009] Bypass email verification secret when confirming account registration
* [https://moodle.org/mod/forum/discuss.php?d=419654 MSA-21-0010] Fetching a user's enrolled courses via web services did not check profile access in each course
* [https://moodle.org/mod/forum/discuss.php?d=419655 MSA-21-0011] JQuery versions below 3.5.0 contain some potential vulnerabilities (upstream)
==See also==
==See also==
*[[Moodle 3.5.16 release notes]]
*[[Moodle 3.5.16 release notes]]

Latest revision as of 09:09, 25 May 2022

Important:

This content of this page has been updated and migrated to the new Moodle Developer Resources. The information contained on the page should no longer be seen up-to-date.

Why not view this page on the new site and help us to migrate more content to the new site!

This version of Moodle is no longer supported for general bug fixes. You are encouraged to upgrade to a supported version of Moodle.

Releases > Moodle 3.5.17 release notes

Release date: 8 March 2021

Here is the full list of fixed issues in 3.5.17.

Security fixes

  • MSA-21-0006 Stored XSS via ID number user profile field
  • MSA-21-0007 Stored XSS and blind SSRF possible via feedback answer text
  • MSA-21-0008 User full name disclosure within online users block
  • MSA-21-0009 Bypass email verification secret when confirming account registration
  • MSA-21-0010 Fetching a user's enrolled courses via web services did not check profile access in each course
  • MSA-21-0011 JQuery versions below 3.5.0 contain some potential vulnerabilities (upstream)

See also