Skip to content

Commit c50f472

Browse files
committed
[docs] Add security announcements to 5.0.2 and friends
1 parent 5d51cdd commit c50f472

File tree

4 files changed

+24
-8
lines changed

4 files changed

+24
-8
lines changed

general/releases/4.1/4.1.20.md

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,5 +20,9 @@ import { ReleaseNoteIntro } from '@site/src/components/ReleaseInformation';
2020
<!-- cspell:enable -->
2121

2222
## Security fixes
23-
24-
A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version.
23+
<!-- cspell:disable -->
24+
- [MSA-25-0037](https://moodle.org/mod/forum/discuss.php?d=469490) - Unnecessary CSRF token (sesskey) requirement in some LMS BigBlueButton playback functionality could leak user's sesskey to external BBB service
25+
- [MSA-25-0038](https://moodle.org/mod/forum/discuss.php?d=469491) - Course Logs report did not respect Separate Groups mode
26+
- [MSA-25-0039](https://moodle.org/mod/forum/discuss.php?d=469492) - Feedback activity results did not always respect Separate Groups mode
27+
- [MSA-25-0040](https://moodle.org/mod/forum/discuss.php?d=469493) - Capabilities and callback that control access to profiles not working in some web services
28+
<!-- cspell:enable -->

general/releases/4.4/4.4.10.md

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,5 +20,9 @@ import { ReleaseNoteIntro } from '@site/src/components/ReleaseInformation';
2020
<!-- cspell:enable -->
2121

2222
## Security fixes
23-
24-
A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version.
23+
<!-- cspell:disable -->
24+
- [MSA-25-0037](https://moodle.org/mod/forum/discuss.php?d=469490) - Unnecessary CSRF token (sesskey) requirement in some LMS BigBlueButton playback functionality could leak user's sesskey to external BBB service
25+
- [MSA-25-0038](https://moodle.org/mod/forum/discuss.php?d=469491) - Course Logs report did not respect Separate Groups mode
26+
- [MSA-25-0039](https://moodle.org/mod/forum/discuss.php?d=469492) - Feedback activity results did not always respect Separate Groups mode
27+
- [MSA-25-0040](https://moodle.org/mod/forum/discuss.php?d=469493) - Capabilities and callback that control access to profiles not working in some web services
28+
<!-- cspell:enable -->

general/releases/4.5/4.5.6.md

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -83,5 +83,9 @@ import { ReleaseNoteIntro } from '@site/src/components/ReleaseInformation';
8383
<!-- cspell:enable -->
8484

8585
## Security fixes
86-
87-
A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version.
86+
<!-- cspell:disable -->
87+
- [MSA-25-0037](https://moodle.org/mod/forum/discuss.php?d=469490) - Unnecessary CSRF token (sesskey) requirement in some LMS BigBlueButton playback functionality could leak user's sesskey to external BBB service
88+
- [MSA-25-0038](https://moodle.org/mod/forum/discuss.php?d=469491) - Course Logs report did not respect Separate Groups mode
89+
- [MSA-25-0039](https://moodle.org/mod/forum/discuss.php?d=469492) - Feedback activity results did not always respect Separate Groups mode
90+
- [MSA-25-0040](https://moodle.org/mod/forum/discuss.php?d=469493) - Capabilities and callback that control access to profiles not working in some web services
91+
<!-- cspell:enable -->

general/releases/5.0/5.0.2.md

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -99,5 +99,9 @@ import { ReleaseNoteIntro } from '@site/src/components/ReleaseInformation';
9999
<!-- cspell:enable -->
100100

101101
## Security fixes
102-
103-
A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version.
102+
<!-- cspell:disable -->
103+
- [MSA-25-0037](https://moodle.org/mod/forum/discuss.php?d=469490) - Unnecessary CSRF token (sesskey) requirement in some LMS BigBlueButton playback functionality could leak user's sesskey to external BBB service
104+
- [MSA-25-0038](https://moodle.org/mod/forum/discuss.php?d=469491) - Course Logs report did not respect Separate Groups mode
105+
- [MSA-25-0039](https://moodle.org/mod/forum/discuss.php?d=469492) - Feedback activity results did not always respect Separate Groups mode
106+
- [MSA-25-0040](https://moodle.org/mod/forum/discuss.php?d=469493) - Capabilities and callback that control access to profiles not working in some web services
107+
<!-- cspell:enable -->

0 commit comments

Comments
 (0)