Note:

If you want to create a new page for developers, you should create it on the Moodle Developer Resource site.

Moodle 2.5.7 release notes: Difference between revisions

From MoodleDocs
(Created page with "Releases > {{FULLPAGENAME}} Release date: Not yet released Here is [https://tracker.moodle.org/secure/IssueNavigator!executeAdvanced.jspa?jqlQuery=project+%3D+mdl+AND+...")
 
m (Protected "Moodle 2.5.7 release notes": Developer Docs Migration ([Edit=Allow only administrators] (indefinite)))
 
(3 intermediate revisions by 2 users not shown)
Line 1: Line 1:
{{Template:Migrated|newDocId=/general/releases/2.5/2.5.7}}
<p class="note">'''This version of Moodle is no longer fully supported.''' Generally, only fixes to serious security issues have been applied to this version. You are encouraged to [[:en:Upgrading|upgrade]] to a fully supported version of Moodle.</p>
[[Releases]] > {{FULLPAGENAME}}
[[Releases]] > {{FULLPAGENAME}}
   
   
Release date: Not yet released
Release date: 14 July, 2014
   
   
Here is [https://tracker.moodle.org/secure/IssueNavigator!executeAdvanced.jspa?jqlQuery=project+%3D+mdl+AND+resolution+%3D+fixed+AND+fixVersion+in+%28%222.5.7%22%29+ORDER+BY+priority+DESC&runQuery=true&clear=true the full list of fixed issues in 2.5.7].
Here is [https://tracker.moodle.org/secure/IssueNavigator!executeAdvanced.jspa?jqlQuery=project+%3D+mdl+AND+resolution+%3D+fixed+AND+fixVersion+in+%28%222.5.7%22%29+ORDER+BY+priority+DESC&runQuery=true&clear=true the full list of fixed issues in 2.5.7].
Line 7: Line 10:
===Highlights===
===Highlights===
   
   
* ...
* MDL-41383 - File picker works when zooming in and out of browser
===Functional changes===
* ...
===API changes===
* ...
   
   
===Security issues===
===Security issues===
   
   
A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version.
* [https://moodle.org/mod/forum/discuss.php?d=264261 MSA-14-0020] Identity confusion in Shibboleth authentication
* [https://moodle.org/mod/forum/discuss.php?d=264262 MSA-14-0021] Code injection in Repositories
===Fixes and improvements===
* [https://moodle.org/mod/forum/discuss.php?d=264263 MSA-14-0022] XML External Entity vulnerability in LTI module
* [https://moodle.org/mod/forum/discuss.php?d=264264 MSA-14-0023] XML External Entity vulnerability in IMSCC and IMSCP
* ...
* [https://moodle.org/mod/forum/discuss.php?d=264265 MSA-14-0024] Cross-site scripting vulnerability in profile field
* [https://moodle.org/mod/forum/discuss.php?d=264266 MSA-14-0025] Remote code execution in Quiz
* [https://moodle.org/mod/forum/discuss.php?d=264267 MSA-14-0026] Information leak in profile and notes pages
* [https://moodle.org/mod/forum/discuss.php?d=264268 MSA-14-0027] Forum group posting issue
* [https://moodle.org/mod/forum/discuss.php?d=264269 MSA-14-0028] Cross-site scripting possible in external badges
* [https://moodle.org/mod/forum/discuss.php?d=264270 MSA-14-0029] Cross-site scripting vulnerability in exception dialogues
* [https://moodle.org/mod/forum/discuss.php?d=264273 MSA-14-0032] Cross-site scripting in advanced grading methods
 
==See also==
==See also==
*[[Moodle 2.5.6 release notes]]
*[[Moodle 2.5.6 release notes]]

Latest revision as of 09:07, 25 May 2022

Important:

This content of this page has been updated and migrated to the new Moodle Developer Resources. The information contained on the page should no longer be seen up-to-date.

Why not view this page on the new site and help us to migrate more content to the new site!

This version of Moodle is no longer fully supported. Generally, only fixes to serious security issues have been applied to this version. You are encouraged to upgrade to a fully supported version of Moodle.

Releases > Moodle 2.5.7 release notes

Release date: 14 July, 2014

Here is the full list of fixed issues in 2.5.7.

Highlights

  • MDL-41383 - File picker works when zooming in and out of browser

Security issues

  • MSA-14-0020 Identity confusion in Shibboleth authentication
  • MSA-14-0021 Code injection in Repositories
  • MSA-14-0022 XML External Entity vulnerability in LTI module
  • MSA-14-0023 XML External Entity vulnerability in IMSCC and IMSCP
  • MSA-14-0024 Cross-site scripting vulnerability in profile field
  • MSA-14-0025 Remote code execution in Quiz
  • MSA-14-0026 Information leak in profile and notes pages
  • MSA-14-0027 Forum group posting issue
  • MSA-14-0028 Cross-site scripting possible in external badges
  • MSA-14-0029 Cross-site scripting vulnerability in exception dialogues
  • MSA-14-0032 Cross-site scripting in advanced grading methods

See also