diff --git a/general/releases/4.1/4.1.16.md b/general/releases/4.1/4.1.16.md index 9bf0c461c0..89b2c49520 100644 --- a/general/releases/4.1/4.1.16.md +++ b/general/releases/4.1/4.1.16.md @@ -19,5 +19,14 @@ import { ReleaseNoteIntro } from '@site/src/components/ReleaseInformation'; ## Security fixes - -A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version. + +- [MSA-25-0001](https://moodle.org/mod/forum/discuss.php?d=466141) - Arbitrary file read risk through pdfTeX +- [MSA-25-0002](https://moodle.org/mod/forum/discuss.php?d=466142) - Feedback response viewing and deletions did not respect Separate Groups mode +- [MSA-25-0003](https://moodle.org/mod/forum/discuss.php?d=466143) - Non-searchable tags can still be discovered on the tag search page and in the tags block +- [MSA-25-0004](https://moodle.org/mod/forum/discuss.php?d=466144) - Stored XSS in ddimageortext question type +- [MSA-25-0005](https://moodle.org/mod/forum/discuss.php?d=466145) - Stored XSS risk in admin live log +- [MSA-25-0007](https://moodle.org/mod/forum/discuss.php?d=466147) - Upgrade RequireJS including security fix (upstream) +- [MSA-25-0008](https://moodle.org/mod/forum/discuss.php?d=466148) - IDOR in badges allows disabling of arbitrary badges +- [MSA-25-0009](https://moodle.org/mod/forum/discuss.php?d=466149) - Teachers can evade trusttext config when restoring glossary entries +- [MSA-25-0010](https://moodle.org/mod/forum/discuss.php?d=466150) - SQL injection risk in course search module list filter + diff --git a/general/releases/4.3/4.3.10.md b/general/releases/4.3/4.3.10.md index 71ff17fa66..e80026b753 100644 --- a/general/releases/4.3/4.3.10.md +++ b/general/releases/4.3/4.3.10.md @@ -19,5 +19,15 @@ import { ReleaseNoteIntro } from '@site/src/components/ReleaseInformation'; ## Security fixes - -A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version. + +- [MSA-25-0001](https://moodle.org/mod/forum/discuss.php?d=466141) - Arbitrary file read risk through pdfTeX +- [MSA-25-0002](https://moodle.org/mod/forum/discuss.php?d=466142) - Feedback response viewing and deletions did not respect Separate Groups mode +- [MSA-25-0003](https://moodle.org/mod/forum/discuss.php?d=466143) - Non-searchable tags can still be discovered on the tag search page and in the tags block +- [MSA-25-0004](https://moodle.org/mod/forum/discuss.php?d=466144) - Stored XSS in ddimageortext question type +- [MSA-25-0005](https://moodle.org/mod/forum/discuss.php?d=466145) - Stored XSS risk in admin live log +- [MSA-25-0006](https://moodle.org/mod/forum/discuss.php?d=466146) - Reflected XSS via question bank filter +- [MSA-25-0007](https://moodle.org/mod/forum/discuss.php?d=466147) - Upgrade RequireJS including security fix (upstream) +- [MSA-25-0008](https://moodle.org/mod/forum/discuss.php?d=466148) - IDOR in badges allows disabling of arbitrary badges +- [MSA-25-0009](https://moodle.org/mod/forum/discuss.php?d=466149) - Teachers can evade trusttext config when restoring glossary entries +- [MSA-25-0010](https://moodle.org/mod/forum/discuss.php?d=466150) - SQL injection risk in course search module list filter + diff --git a/general/releases/4.4/4.4.6.md b/general/releases/4.4/4.4.6.md index e71a10b45a..27426fb6bf 100644 --- a/general/releases/4.4/4.4.6.md +++ b/general/releases/4.4/4.4.6.md @@ -78,5 +78,15 @@ import { ReleaseNoteIntro } from '@site/src/components/ReleaseInformation'; ## Security fixes - -A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version. + +- [MSA-25-0001](https://moodle.org/mod/forum/discuss.php?d=466141) - Arbitrary file read risk through pdfTeX +- [MSA-25-0002](https://moodle.org/mod/forum/discuss.php?d=466142) - Feedback response viewing and deletions did not respect Separate Groups mode +- [MSA-25-0003](https://moodle.org/mod/forum/discuss.php?d=466143) - Non-searchable tags can still be discovered on the tag search page and in the tags block +- [MSA-25-0004](https://moodle.org/mod/forum/discuss.php?d=466144) - Stored XSS in ddimageortext question type +- [MSA-25-0005](https://moodle.org/mod/forum/discuss.php?d=466145) - Stored XSS risk in admin live log +- [MSA-25-0006](https://moodle.org/mod/forum/discuss.php?d=466146) - Reflected XSS via question bank filter +- [MSA-25-0007](https://moodle.org/mod/forum/discuss.php?d=466147) - Upgrade RequireJS including security fix (upstream) +- [MSA-25-0008](https://moodle.org/mod/forum/discuss.php?d=466148) - IDOR in badges allows disabling of arbitrary badges +- [MSA-25-0009](https://moodle.org/mod/forum/discuss.php?d=466149) - Teachers can evade trusttext config when restoring glossary entries +- [MSA-25-0010](https://moodle.org/mod/forum/discuss.php?d=466150) - SQL injection risk in course search module list filter + diff --git a/general/releases/4.5/4.5.2.md b/general/releases/4.5/4.5.2.md index b66e0d6489..8cdc797653 100644 --- a/general/releases/4.5/4.5.2.md +++ b/general/releases/4.5/4.5.2.md @@ -86,5 +86,15 @@ import { ReleaseNoteIntro } from '@site/src/components/ReleaseInformation'; ## Security fixes - -A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version. + +- [MSA-25-0001](https://moodle.org/mod/forum/discuss.php?d=466141) - Arbitrary file read risk through pdfTeX +- [MSA-25-0002](https://moodle.org/mod/forum/discuss.php?d=466142) - Feedback response viewing and deletions did not respect Separate Groups mode +- [MSA-25-0003](https://moodle.org/mod/forum/discuss.php?d=466143) - Non-searchable tags can still be discovered on the tag search page and in the tags block +- [MSA-25-0004](https://moodle.org/mod/forum/discuss.php?d=466144) - Stored XSS in ddimageortext question type +- [MSA-25-0005](https://moodle.org/mod/forum/discuss.php?d=466145) - Stored XSS risk in admin live log +- [MSA-25-0006](https://moodle.org/mod/forum/discuss.php?d=466146) - Reflected XSS via question bank filter +- [MSA-25-0007](https://moodle.org/mod/forum/discuss.php?d=466147) - Upgrade RequireJS including security fix (upstream) +- [MSA-25-0008](https://moodle.org/mod/forum/discuss.php?d=466148) - IDOR in badges allows disabling of arbitrary badges +- [MSA-25-0009](https://moodle.org/mod/forum/discuss.php?d=466149) - Teachers can evade trusttext config when restoring glossary entries +- [MSA-25-0010](https://moodle.org/mod/forum/discuss.php?d=466150) - SQL injection risk in course search module list filter +