Skip to content

Commit 55e169d

Browse files
authored
Merge pull request #1493 from mickhawkins/main
[docs] Add security announcements to 5.1.1 and friends
2 parents 02fd1d4 + 000b4c6 commit 55e169d

File tree

5 files changed

+63
-10
lines changed

5 files changed

+63
-10
lines changed

general/releases/4.1/4.1.22.md

Lines changed: 12 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -18,5 +18,15 @@ import { ReleaseNoteIntro } from '@site/src/components/ReleaseInformation';
1818
<!-- cspell:enable -->
1919

2020
## Security fixes
21-
22-
A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version.
21+
<!-- cspell:disable -->
22+
- [MSA-25-0051](https://moodle.org/mod/forum/discuss.php?d=471297) - Remote code execution risk via file restore
23+
- [MSA-25-0052](https://moodle.org/mod/forum/discuss.php?d=471298) - Authentication via LTI Provider available to suspended users
24+
- [MSA-25-0054](https://moodle.org/mod/forum/discuss.php?d=471300) - XSS risk in formula editor
25+
- [MSA-25-0055](https://moodle.org/mod/forum/discuss.php?d=471301) - Formula injection risk when exporting data to CSV / Excel
26+
- [MSA-25-0056](https://moodle.org/mod/forum/discuss.php?d=471302) - Open redirect in OAuth login
27+
- [MSA-25-0057](https://moodle.org/mod/forum/discuss.php?d=471303) - Password brute force risk from confirmation email web service
28+
- [MSA-25-0058](https://moodle.org/mod/forum/discuss.php?d=471304) - Participants can access forum ratings without permission
29+
- [MSA-25-0059](https://moodle.org/mod/forum/discuss.php?d=471305) - Reflected XSS risk in policy tool
30+
- [MSA-25-0060](https://moodle.org/mod/forum/discuss.php?d=471306) - Badges with a role criterion could be awarded to users who do not hold the role
31+
- [MSA-25-0061](https://moodle.org/mod/forum/discuss.php?d=471307) - User IDs exposed in URLs when using anonymous submissions in assignment
32+
<!-- cspell:enable -->

general/releases/4.4/4.4.12.md

Lines changed: 12 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -28,5 +28,15 @@ import { ReleaseNoteIntro } from '@site/src/components/ReleaseInformation';
2828
<!-- cspell:enable -->
2929

3030
## Security fixes
31-
32-
A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version.
31+
<!-- cspell:disable -->
32+
- [MSA-25-0051](https://moodle.org/mod/forum/discuss.php?d=471297) - Remote code execution risk via file restore
33+
- [MSA-25-0052](https://moodle.org/mod/forum/discuss.php?d=471298) - Authentication via LTI Provider available to suspended users
34+
- [MSA-25-0054](https://moodle.org/mod/forum/discuss.php?d=471300) - XSS risk in formula editor
35+
- [MSA-25-0055](https://moodle.org/mod/forum/discuss.php?d=471301) - Formula injection risk when exporting data to CSV / Excel
36+
- [MSA-25-0056](https://moodle.org/mod/forum/discuss.php?d=471302) - Open redirect in OAuth login
37+
- [MSA-25-0057](https://moodle.org/mod/forum/discuss.php?d=471303) - Password brute force risk from confirmation email web service
38+
- [MSA-25-0058](https://moodle.org/mod/forum/discuss.php?d=471304) - Participants can access forum ratings without permission
39+
- [MSA-25-0059](https://moodle.org/mod/forum/discuss.php?d=471305) - Reflected XSS risk in policy tool
40+
- [MSA-25-0060](https://moodle.org/mod/forum/discuss.php?d=471306) - Badges with a role criterion could be awarded to users who do not hold the role
41+
- [MSA-25-0061](https://moodle.org/mod/forum/discuss.php?d=471307) - User IDs exposed in URLs when using anonymous submissions in assignment
42+
<!-- cspell:enable -->

general/releases/4.5/4.5.8.md

Lines changed: 13 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -59,5 +59,16 @@ import { ReleaseNoteIntro } from '@site/src/components/ReleaseInformation';
5959
<!-- cspell:enable -->
6060

6161
## Security fixes
62-
63-
A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version.
62+
<!-- cspell:disable -->
63+
- [MSA-25-0051](https://moodle.org/mod/forum/discuss.php?d=471297) - Remote code execution risk via file restore
64+
- [MSA-25-0052](https://moodle.org/mod/forum/discuss.php?d=471298) - Authentication via LTI Provider available to suspended users
65+
- [MSA-25-0053](https://moodle.org/mod/forum/discuss.php?d=471299) - XSS risk via AI prompt injection
66+
- [MSA-25-0054](https://moodle.org/mod/forum/discuss.php?d=471300) - XSS risk in formula editor
67+
- [MSA-25-0055](https://moodle.org/mod/forum/discuss.php?d=471301) - Formula injection risk when exporting data to CSV / Excel
68+
- [MSA-25-0056](https://moodle.org/mod/forum/discuss.php?d=471302) - Open redirect in OAuth login
69+
- [MSA-25-0057](https://moodle.org/mod/forum/discuss.php?d=471303) - Password brute force risk from confirmation email web service
70+
- [MSA-25-0058](https://moodle.org/mod/forum/discuss.php?d=471304) - Participants can access forum ratings without permission
71+
- [MSA-25-0059](https://moodle.org/mod/forum/discuss.php?d=471305) - Reflected XSS risk in policy tool
72+
- [MSA-25-0060](https://moodle.org/mod/forum/discuss.php?d=471306) - Badges with a role criterion could be awarded to users who do not hold the role
73+
- [MSA-25-0061](https://moodle.org/mod/forum/discuss.php?d=471307) - User IDs exposed in URLs when using anonymous submissions in assignment
74+
<!-- cspell:enable -->

general/releases/5.0/5.0.4.md

Lines changed: 13 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -113,5 +113,16 @@ import { ReleaseNoteIntro } from '@site/src/components/ReleaseInformation';
113113
<!-- cspell:enable -->
114114

115115
## Security fixes
116-
117-
A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version.
116+
<!-- cspell:disable -->
117+
- [MSA-25-0051](https://moodle.org/mod/forum/discuss.php?d=471297) - Remote code execution risk via file restore
118+
- [MSA-25-0052](https://moodle.org/mod/forum/discuss.php?d=471298) - Authentication via LTI Provider available to suspended users
119+
- [MSA-25-0053](https://moodle.org/mod/forum/discuss.php?d=471299) - XSS risk via AI prompt injection
120+
- [MSA-25-0054](https://moodle.org/mod/forum/discuss.php?d=471300) - XSS risk in formula editor
121+
- [MSA-25-0055](https://moodle.org/mod/forum/discuss.php?d=471301) - Formula injection risk when exporting data to CSV / Excel
122+
- [MSA-25-0056](https://moodle.org/mod/forum/discuss.php?d=471302) - Open redirect in OAuth login
123+
- [MSA-25-0057](https://moodle.org/mod/forum/discuss.php?d=471303) - Password brute force risk from confirmation email web service
124+
- [MSA-25-0058](https://moodle.org/mod/forum/discuss.php?d=471304) - Participants can access forum ratings without permission
125+
- [MSA-25-0059](https://moodle.org/mod/forum/discuss.php?d=471305) - Reflected XSS risk in policy tool
126+
- [MSA-25-0060](https://moodle.org/mod/forum/discuss.php?d=471306) - Badges with a role criterion could be awarded to users who do not hold the role
127+
- [MSA-25-0061](https://moodle.org/mod/forum/discuss.php?d=471307) - User IDs exposed in URLs when using anonymous submissions in assignment
128+
<!-- cspell:enable -->

general/releases/5.1/5.1.1.md

Lines changed: 13 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -113,5 +113,16 @@ import { ReleaseNoteIntro } from '@site/src/components/ReleaseInformation';
113113
<!-- cspell:enable -->
114114

115115
## Security fixes
116-
117-
A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version.
116+
<!-- cspell:disable -->
117+
- [MSA-25-0051](https://moodle.org/mod/forum/discuss.php?d=471297) - Remote code execution risk via file restore
118+
- [MSA-25-0052](https://moodle.org/mod/forum/discuss.php?d=471298) - Authentication via LTI Provider available to suspended users
119+
- [MSA-25-0053](https://moodle.org/mod/forum/discuss.php?d=471299) - XSS risk via AI prompt injection
120+
- [MSA-25-0054](https://moodle.org/mod/forum/discuss.php?d=471300) - XSS risk in formula editor
121+
- [MSA-25-0055](https://moodle.org/mod/forum/discuss.php?d=471301) - Formula injection risk when exporting data to CSV / Excel
122+
- [MSA-25-0056](https://moodle.org/mod/forum/discuss.php?d=471302) - Open redirect in OAuth login
123+
- [MSA-25-0057](https://moodle.org/mod/forum/discuss.php?d=471303) - Password brute force risk from confirmation email web service
124+
- [MSA-25-0058](https://moodle.org/mod/forum/discuss.php?d=471304) - Participants can access forum ratings without permission
125+
- [MSA-25-0059](https://moodle.org/mod/forum/discuss.php?d=471305) - Reflected XSS risk in policy tool
126+
- [MSA-25-0060](https://moodle.org/mod/forum/discuss.php?d=471306) - Badges with a role criterion could be awarded to users who do not hold the role
127+
- [MSA-25-0061](https://moodle.org/mod/forum/discuss.php?d=471307) - User IDs exposed in URLs when using anonymous submissions in assignment
128+
<!-- cspell:enable -->

0 commit comments

Comments
 (0)