Note:

If you want to create a new page for developers, you should create it on the Moodle Developer Resource site.

Moodle 3.3.6 release notes: Difference between revisions

From MoodleDocs
No edit summary
Line 28: Line 28:
===Security issues===
===Security issues===
   
   
A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version.
* [https://moodle.org/mod/forum/discuss.php?d=371199 MSA-18-0007] Calculated question type allows remote code execution by Question authors
 
* [https://moodle.org/mod/forum/discuss.php?d=371200 MSA-18-0008] Users can download any file via portfolio assignment caller class
* [https://moodle.org/mod/forum/discuss.php?d=371201 MSA-18-0009] Portfolio forum caller class allows a user to download any file
* [https://moodle.org/mod/forum/discuss.php?d=371202 MSA-18-0010] User can shift a block from Dashboard to any page
* [https://moodle.org/mod/forum/discuss.php?d=371203 MSA-18-0011] User who did not agree to the site policies can see the site homepage as if they had full site access
* [https://moodle.org/mod/forum/discuss.php?d=371204 MSA-18-0012] Portfolio script allows instantiation of class chosen by user
 
==See also==
==See also==
*[[Moodle 3.3.5 release notes]]
*[[Moodle 3.3.5 release notes]]

Revision as of 05:59, 25 May 2018

Releases > Moodle 3.3.6 release notes

Release date: 17 May 2018

Here is the full list of fixed issues in 3.3.6.

GDPR preparation

Plugins are available for Moodle 3.3 and 3.4 to help Moodle sites to comply with GDPR - Data privacy, Policies. In Moodle 3.5 they will be included in the standard distribution. Work on changes in core is almost completed, the new minor release with the remaining components will follow in several days.

  • MDL-61306 - Implement privacy API in various components and standard plugins for user data export and deletion

Fixes and improvements

  • MDL-58697 - Assignment: Fixed incorrect "No submission" status if group submission changed to individual submission
  • MDL-61724 - File resource: Fixed download problem for files with long names
  • MDL-55532 - Show grade category name in Grades Export
  • MDL-61714 - GDPR and privacy: Change default age of digital consent according to current legislation on each country
  • MDL-52989 - Lesson: Fixed regression in cluster navigation
  • MDL-60196 - Display custom external tool icon in activity chooser
  • MDL-61800 - A bug which led to the failure of some Scheduled Tasks in certain circmstances has been fixed.
  • MDL-61733 - Database module: Fixed bug with creating tables in templates using Atto editor
  • MDL-61348 - Quiz: Fixed a report bug where the count of the number of attempts is sometimes incorrect in group averages
  • MDL-61520 - Quiz: Fixed a bug where the question text was no longer exported in the quiz statistics HTML download
  • MDL-62202 - GDPR: Moved the Privacy and policies administration section to the Users tab (when GDPR plugins are installed)
  • MDL-62042 - Global search: Remove unicode non-characters from indexing to resolve indexing errors
  • MDL-61827 - Facebook OAuth2: Update the Facebook Graph API to v2.12

Security issues

  • MSA-18-0007 Calculated question type allows remote code execution by Question authors
  • MSA-18-0008 Users can download any file via portfolio assignment caller class
  • MSA-18-0009 Portfolio forum caller class allows a user to download any file
  • MSA-18-0010 User can shift a block from Dashboard to any page
  • MSA-18-0011 User who did not agree to the site policies can see the site homepage as if they had full site access
  • MSA-18-0012 Portfolio script allows instantiation of class chosen by user

See also