Note:

If you want to create a new page for developers, you should create it on the Moodle Developer Resource site.

Moodle 2.5.7 release notes: Difference between revisions

From MoodleDocs
(Adding issues)
(Adding security release notes)
Line 13: Line 13:
===Security issues===
===Security issues===
   
   
A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version.
* [https://moodle.org/mod/forum/discuss.php?d=264261 MSA-14-0020] Identity confusion in Shibboleth authentication
* [https://moodle.org/mod/forum/discuss.php?d=264262 MSA-14-0021] Code injection in Repositories
* [https://moodle.org/mod/forum/discuss.php?d=264263 MSA-14-0022] XML External Entity vulnerability in LTI module
* [https://moodle.org/mod/forum/discuss.php?d=264264 MSA-14-0023] XML External Entity vulnerability in IMSCC and IMSCP
* [https://moodle.org/mod/forum/discuss.php?d=264265 MSA-14-0024] Cross-site scripting vulnerability in profile field
* [https://moodle.org/mod/forum/discuss.php?d=264266 MSA-14-0025] Remote code execution in Quiz
* [https://moodle.org/mod/forum/discuss.php?d=264267 MSA-14-0026] Information leak in profile and notes pages
* [https://moodle.org/mod/forum/discuss.php?d=264268 MSA-14-0027] Forum group posting issue
* [https://moodle.org/mod/forum/discuss.php?d=264269 MSA-14-0028] Cross-site scripting possible in external badges
* [https://moodle.org/mod/forum/discuss.php?d=264270 MSA-14-0029] Cross-site scripting vulnerability in exception dialogues
* [https://moodle.org/mod/forum/discuss.php?d=264273 MSA-14-0032] Cross-site scripting in advanced grading methods
 
==See also==
==See also==
*[[Moodle 2.5.6 release notes]]
*[[Moodle 2.5.6 release notes]]

Revision as of 02:11, 21 July 2014

This version of Moodle is no longer fully supported. Generally, only fixes to serious security issues have been applied to this version. You are encouraged to upgrade to a fully supported version of Moodle.

Releases > Moodle 2.5.7 release notes

Release date: 14 July, 2014

Here is the full list of fixed issues in 2.5.7.

Highlights

  • MDL-41383 - File picker works when zooming in and out of browser

Security issues

  • MSA-14-0020 Identity confusion in Shibboleth authentication
  • MSA-14-0021 Code injection in Repositories
  • MSA-14-0022 XML External Entity vulnerability in LTI module
  • MSA-14-0023 XML External Entity vulnerability in IMSCC and IMSCP
  • MSA-14-0024 Cross-site scripting vulnerability in profile field
  • MSA-14-0025 Remote code execution in Quiz
  • MSA-14-0026 Information leak in profile and notes pages
  • MSA-14-0027 Forum group posting issue
  • MSA-14-0028 Cross-site scripting possible in external badges
  • MSA-14-0029 Cross-site scripting vulnerability in exception dialogues
  • MSA-14-0032 Cross-site scripting in advanced grading methods

See also