Difference between revisions of "Moodle 2.5.9 release notes"

Jump to: navigation, search
(Created page with "<p class="note">'''This version of Moodle is no longer supported.''' You are encouraged to upgrade to a supported version of Moodle.</p> Releases > {{FU...")
 
(Security issues)
 
(One intermediate revision by one other user not shown)
Line 3: Line 3:
 
[[Releases]] > {{FULLPAGENAME}}
 
[[Releases]] > {{FULLPAGENAME}}
 
   
 
   
Release date: Not yet released
+
Release date: 10 November, 2014
 
   
 
   
 
Here is [https://tracker.moodle.org/secure/IssueNavigator!executeAdvanced.jspa?jqlQuery=project+%3D+mdl+AND+resolution+%3D+fixed+AND+fixVersion+in+%28%222.5.9%22%29+ORDER+BY+priority+DESC&runQuery=true&clear=true the full list of fixed issues in 2.5.9].
 
Here is [https://tracker.moodle.org/secure/IssueNavigator!executeAdvanced.jspa?jqlQuery=project+%3D+mdl+AND+resolution+%3D+fixed+AND+fixVersion+in+%28%222.5.9%22%29+ORDER+BY+priority+DESC&runQuery=true&clear=true the full list of fixed issues in 2.5.9].
+
 
===Highlights===
 
 
* ...
 
 
===Functional changes===
 
 
* ...
 
 
===API changes===
 
 
* ...
 
 
 
===Security issues===
 
===Security issues===
 
   
 
   
A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version.
+
* [https://moodle.org/mod/forum/discuss.php?d=275146 MSA-14-0035] Headers not added to some AJAX scripts
+
* [https://moodle.org/mod/forum/discuss.php?d=275147 MSA-14-0036] XSS in mapcourse script in Feedback module
===Fixes and improvements===
+
* [https://moodle.org/mod/forum/discuss.php?d=275152 MSA-14-0037] Weak temporary password generation
+
* [https://moodle.org/mod/forum/discuss.php?d=275154 MSA-14-0039] Insufficient access check in LTI module
* ...
+
* [https://moodle.org/mod/forum/discuss.php?d=275155 MSA-14-0040] Information leak in Database activity module
+
* [https://moodle.org/mod/forum/discuss.php?d=275157 MSA-14-0041] Lack of capability check in tags list access
 +
* [https://moodle.org/mod/forum/discuss.php?d=275158 MSA-14-0042] Lack of access check in IP lookup functionality
 +
* [https://moodle.org/mod/forum/discuss.php?d=275162 MSA-14-0046] CSRF in LTI module
 +
* [https://moodle.org/mod/forum/discuss.php?d=275163 MSA-14-0047] Possible data loss in Wiki activity
 +
* [https://moodle.org/mod/forum/discuss.php?d=275164 MSA-14-0048] CSRF in forum tracking toggle
 +
* [https://moodle.org/mod/forum/discuss.php?d=275165 MSA-14-0049] Possible to print arbitrary message to user by modifying URL
 +
 
 
==See also==
 
==See also==
 
*[[Moodle 2.5.8 release notes]]
 
*[[Moodle 2.5.8 release notes]]

Latest revision as of 04:45, 17 November 2014

This version of Moodle is no longer supported. You are encouraged to upgrade to a supported version of Moodle.

Releases > Moodle 2.5.9 release notes

Release date: 10 November, 2014

Here is the full list of fixed issues in 2.5.9.

Security issues

See also