Note:

If you want to create a new page for developers, you should create it on the Moodle Developer Resource site.

Moodle 2.6.7 release notes: Difference between revisions

From MoodleDocs
No edit summary
m (Protected "Moodle 2.6.7 release notes": Developer Docs Migration ([Edit=Allow only administrators] (indefinite)))
 
(3 intermediate revisions by 2 users not shown)
Line 1: Line 1:
{{Template:Migrated|newDocId=/general/releases/2.6/2.6.7}}
<p class="note">'''This version of Moodle is no longer supported.''' You are encouraged to [[:en:Upgrading|upgrade]] to a supported version of Moodle.</p>
<p class="note">'''This version of Moodle is no longer supported.''' You are encouraged to [[:en:Upgrading|upgrade]] to a supported version of Moodle.</p>


[[Releases]] > {{FULLPAGENAME}}
[[Releases]] > {{FULLPAGENAME}}
   
   
Release date: Not yet released
Release date: January 12, 2015
   
   
Here is [https://tracker.moodle.org/secure/IssueNavigator!executeAdvanced.jspa?jqlQuery=project+%3D+mdl+AND+resolution+%3D+fixed+AND+fixVersion+in+%28%222.6.7%22%29+ORDER+BY+priority+DESC&runQuery=true&clear=true the full list of fixed issues in 2.6.7].
Here is [https://tracker.moodle.org/secure/IssueNavigator!executeAdvanced.jspa?jqlQuery=project+%3D+mdl+AND+resolution+%3D+fixed+AND+fixVersion+in+%28%222.6.7%22%29+ORDER+BY+priority+DESC&runQuery=true&clear=true the full list of fixed issues in 2.6.7].
Line 9: Line 10:
===Security issues===
===Security issues===
   
   
A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version.
* [https://moodle.org/mod/forum/discuss.php?d=278611 MSA-15-0001] Insufficient access check in LTI module
* [https://moodle.org/mod/forum/discuss.php?d=278612 MSA-15-0002] XSS vulnerability in course request pending approval page
* [https://moodle.org/mod/forum/discuss.php?d=278613 MSA-15-0003] CSRF possible in Glossary module
* [https://moodle.org/mod/forum/discuss.php?d=278614 MSA-15-0004] Information leak through messaging functions in web-services
* [https://moodle.org/mod/forum/discuss.php?d=278615 MSA-15-0005] Insufficient access check in calendar functions in web-services
* [https://moodle.org/mod/forum/discuss.php?d=278617 MSA-15-0007] ReDoS possible in the multimedia filter
* [https://moodle.org/mod/forum/discuss.php?d=278618 MSA-15-0008] Forced logout through Shibboleth authentication plugin
 
==See also==
==See also==
*[[Moodle 2.6.6 release notes]]
*[[Moodle 2.6.6 release notes]]

Latest revision as of 09:07, 25 May 2022

Important:

This content of this page has been updated and migrated to the new Moodle Developer Resources. The information contained on the page should no longer be seen up-to-date.

Why not view this page on the new site and help us to migrate more content to the new site!

This version of Moodle is no longer supported. You are encouraged to upgrade to a supported version of Moodle.

Releases > Moodle 2.6.7 release notes

Release date: January 12, 2015

Here is the full list of fixed issues in 2.6.7.

Security issues

  • MSA-15-0001 Insufficient access check in LTI module
  • MSA-15-0002 XSS vulnerability in course request pending approval page
  • MSA-15-0003 CSRF possible in Glossary module
  • MSA-15-0004 Information leak through messaging functions in web-services
  • MSA-15-0005 Insufficient access check in calendar functions in web-services
  • MSA-15-0007 ReDoS possible in the multimedia filter
  • MSA-15-0008 Forced logout through Shibboleth authentication plugin

See also