Educación a distancia Somos Expertos en servicios Moodle

  • Inicio
  • Moodle
    • Productos
    • Servicios
    • Sobre Moodle
    • Sobre Moodle Chile
  • Blog
    • Noticias
      • Seguridad Moodle
      • Planeta Moodle
      • Moodle.org Directo
      • Moodle Buzz
      • Moodle Foro
      • Google News
      • Todas las Noticias
    • Artículos
  • Cotizar

MSA-13-0004: Information leak through activity report

Detalles
Publicado el 20 Enero 2013
Categoría: Seguridad
  • Imprimir
  • Correo electrónico
by Michael de Raadt.  

...
Description:Under certain circumstances, when last access is included in a list of fields forced to be hidden, the Activity report would still reveal users' last access.
Issue summary:

Activity Report showing lastaccess even if it is a hidden field

Severity/Risk:Minor
Versions affected:2.4, 2.3 to 2.3.3+, 2.2 to 2.2.6+
Reporte
Leer más...

MSA-13-0005: Potential phishing attack through URL redirects

Detalles
Publicado el 20 Enero 2013
Categoría: Seguridad
  • Imprimir
  • Correo electrónico
by Michael de Raadt.  

...
Description:Insufficient filtering of return URLs on some pages was allowing redirects to sites outside Moodle.
Issue summary:

Open redirect issues

Severity/Risk:Minor
Versions affected:2.4, 2.3 to 2.3.3+, 2.2 to 2.2.6+
Reported by:Simon Coggins
Issue no.:MDL-35991

CVE identifier:

CVE-2012-6101
Changes (master):http://git.moodle.o
Leer más...

MSA-13-0006: Potential information leak in Assignment module

Detalles
Publicado el 20 Enero 2013
Categoría: Seguridad
  • Imprimir
  • Correo electrónico
by Michael de Raadt.  

...
Description:Through URL manipulation, students were able to view feedback comments provided on other student's submissions.
Issue summary:

Assignment comment permissions are not being validated

Severity/Risk:Serious
Versions affected:2.4, 2.3 to 2.3.3+
Reported by:Dan Poltawski
Issue no.:MDL-37244

CVE identifier:

CVE-2012-6102
Cha
Leer más...

MSA-13-0007: Potential exploit in messaging

Detalles
Publicado el 20 Enero 2013
Categoría: Seguridad
  • Imprimir
  • Correo electrónico
by Michael de Raadt.  

...
Description:The messaging system was not checking the user's session correctly when messages are sent.
Issue summary:

Course message sending can be exploited by CSRF

Severity/Risk:Minor
Versions affected:2.4, 2.3 to 2.3.3+, 2.2 to 2.2.6+
Reported by:Andrew Nicols
Issue no.:MDL-36600

CVE identifier:

CVE-2012-6103
Changes (master):h
Leer más...

MSA-13-0008: Information leak through Blog RSS

Detalles
Publicado el 20 Enero 2013
Categoría: Seguridad
  • Imprimir
  • Correo electrónico
by Michael de Raadt.  

...
Description:Blog posts that were hidden from guest users in the Web interface were being included in the related RSS feed.
Issue summary:

Guest users can access RSS feed for site level blogs

Severity/Risk:Minor
Versions affected:2.4, 2.3 to 2.3.3+, 2.2 to 2.2.6+
Reported by:Charles Fulton
Issue no.:MDL-36620

CVE identifier:

CVE-2
Leer más...

MSA-13-0010: Failure to check capabilities in calendar

Detalles
Publicado el 20 Enero 2013
Categoría: Seguridad
  • Imprimir
  • Correo electrónico
by Michael de Raadt.  

...
Description:Students were able to delete course level calendar subscriptions created by teachers.
Issue summary:

Student user able to Remove imported calendar from Manage Subscriptions

Severity/Risk:Minor
Versions affected:2.4
Reported by:David O'Brien
Issue no.:MDL-37106

CVE identifier:

CVE-2012-6106
Changes (master):http://git.m
Leer más...

MSA-13-0009: Information leak through Blog RSS

Detalles
Publicado el 20 Enero 2013
Categoría: Seguridad
  • Imprimir
  • Correo electrónico
by Michael de Raadt.  

...
Description:Blog posts were still accessible via the blog RSS feed, even after blogging was disabled globally.
Issue summary:

Blog posts still available via RSS even after the blogging is disabled

Severity/Risk:Minor
Versions affected:2.4, 2.3 to 2.3.3+, 2.2 to 2.2.6+, 2.1 to 2.1.9+
Reported by:David Mudrak
Issue no.:MDL-37467

C

Leer más...

MSA-12-0063: Information leak in Check Permissions page

Detalles
Escrito por Moodle-Chile
Publicado el 18 Noviembre 2012
Categoría: Seguridad
  • Imprimir
  • Correo electrónico
by Michael de Raadt.  

Topic:Check Permissions page displays entire user base without moodle/role:manage capability
Severity/Risk:Minor
Versions affected:2.3 to 2.3.2+
Reported by:Jody Steele
Issue no.:MDL-35381

CVE Identifier:

CVE-2012-5481
Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-35381

Des...

Leer más...

MSA-12-0055: Web service access token issue

Detalles
Escrito por Moodle-Chile
Publicado el 16 Septiembre 2012
Categoría: Seguridad
  • Imprimir
  • Correo electrónico
by Michael de Raadt.  

...
Topic:A web service token allows the user to run functions from any external service, not just those linked to the external service the token is for
Severity/Risk:Serious
Versions affected:2.3 to 2.3.1+, 2.2 to 2.2.4+, 2.1 to 2.1.7+
Reported by:Nathan Mares
Issue no.:MDL-34368

CVE Identifier:

CVE-2012-4402
Changes (master):http:
Leer más...

MSA-12-0056: Information leak in drag-and-drop

Detalles
Escrito por Moodle-Chile
Publicado el 16 Septiembre 2012
Categoría: Seguridad
  • Imprimir
  • Correo electrónico
by Michael de Raadt.  

Topic:Information disclosure in yui_combo.php
Severity/Risk:Minor
Versions affected:2.3 to 2.3.1+
Reported by:Mark Baseggio
Issue no.:MDL-35168

CVE Identifier:

CVE-2012-4403
Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-35168

Description:

The drag-and-drop script was...

Leer más...

MSA-12-0057: Access issue through repository

Detalles
Escrito por Moodle-Chile
Publicado el 18 Noviembre 2012
Categoría: Seguridad
  • Imprimir
  • Correo electrónico
by Michael de Raadt.  

...
Topic:User B is able to see and use Dropbox of User A within Dropbox Repository File Picker
Severity/Risk:Serious
Versions affected:2.3 to 2.3.2+, 2.2 to 2.2.5+, 2.1 to 2.1.8+
Reported by:Alexander Bias
Issue no.:MDL-29872, MDL-36366

CVE Identifier:

CVE-2012-5471

Workaround:

Turn off Dropbox repository

Changes (master):http://git.
Leer más...

MSA-12-0058: Possible form data manipulation issue

Detalles
Escrito por Moodle-Chile
Publicado el 18 Noviembre 2012
Categoría: Seguridad
  • Imprimir
  • Correo electrónico
by Michael de Raadt.  

Topic:add setConstant() for hardfreeze element
Severity/Risk:Minor
Versions affected:2.3 to 2.3.2+, 2.2 to 2.2.5+
Reported by:Rossiani Wijaya
Issue no.:MDL-32785

CVE Identifier:

CVE-2012-5472
Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-32785

Description:

Frozen form...

Leer más...

MSA-12-0059: Information leak in Database activity module

Detalles
Escrito por Moodle-Chile
Publicado el 18 Noviembre 2012
Categoría: Seguridad
  • Imprimir
  • Correo electrónico
by Michael de Raadt.  

...
Topic:Members of seperate groups can see Database activity entries for other groups
Severity/Risk:Minor
Versions affected:2.3 to 2.3.2+, 2.2 to 2.2.5+, 2.1 to 2.1.8+
Reported by:Richard Meyer
Issue no.:MDL-34448

CVE Identifier:

CVE-2012-5473
Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=co
Leer más...

MSA-12-0060: Cross-site scripting vulnerability in YUI2

Detalles
Escrito por Moodle-Chile
Publicado el 18 Noviembre 2012
Categoría: Seguridad
  • Imprimir
  • Correo electrónico
by Michael de Raadt.  

...
Topic:yui2 swf vulnerability
Severity/Risk:Serious
Versions affected:2.3 to 2.3.2+, 2.2 to 2.2.5+, 2.1 to 2.1.8+ 1.9 to 1.9.18+
Reported by:Petr Škoda, Jenny Donnelly
Issue no.:MDL-36346

CVE Identifier:

CVE-2012-5475

Workaround:

Delete YUI SWF files

Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&amp
Leer más...

MSA-12-0061: Remote code execution through Portfolio API

Detalles
Escrito por Moodle-Chile
Publicado el 18 Noviembre 2012
Categoría: Seguridad
  • Imprimir
  • Correo electrónico
by Michael de Raadt.  

...
Topic:Portfolio plugin: Local File Inclusion (LFI) and the possibility of Remote Command Execution (RCE).
Severity/Risk:Serious
Versions affected:2.3 to 2.3.2+, 2.2 to 2.2.5+, 2.1 to 2.1.8+
Reported by:Cristobal Leiva
Issue no.:MDL-33791

CVE Identifier:

CVE-2012-5479
Changes (master):http://git.moodle.org/gw?p=moodle.git&a=s
Leer más...

MSA-12-0062: Information leak in Database activity module

Detalles
Escrito por Moodle-Chile
Publicado el 18 Noviembre 2012
Categoría: Seguridad
  • Imprimir
  • Correo electrónico
by Michael de Raadt.  

...
Topic:Any user (including a guest) can view entries in database activity when more entries are required before viewing other participants entries
Severity/Risk:Minor
Versions affected:2.3 to 2.3.2+, 2.2 to 2.2.5+, 2.1 to 2.1.8+
Reported by:Tabitha Roder
Issue no.:MDL-35558

CVE Identifier:

CVE-2012-5480
Changes (master):http://gi
Leer más...

MSA-12-0054: Course reset permission issue

Detalles
Escrito por Moodle-Chile
Publicado el 16 Septiembre 2012
Categoría: Seguridad
  • Imprimir
  • Correo electrónico
by Michael de Raadt.  

Topic:Course reset not protected by proper capability
Severity/Risk:Minor
Versions affected:2.3 to 2.3.1+, 2.2 to 2.2.4+, 2.1 to 2.1.7+
Reported by:Rex Lorenzo
Issue no.:MDL-34519

CVE Identifier:

CVE-2012-4408
Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-34519

Description:

...

Leer más...

Integration, exposed: Integration round 2013-08-08 - week 32 of 52.

Detalles
Publicado el 08 Agosto 2013
Categoría: Planeta Moodle
  • Imprimir
  • Correo electrónico
by Sam Hemelryk.  

Cold numbers:

48 issues have been successfully integrated with 6 rejected and 0 delayed. That is 89% success.

Notes:
Its worth nothing that several accessibility issues were resolved this week with better notation of dynamic content. We hope to see more of these landing in the next few weeks.
There was also a nasty segfault...
Leer más...

Gavin Henrick: Moodle Research Conference – Call for Workshop Proposals

Detalles
Publicado el 06 Agosto 2013
Categoría: Planeta Moodle
  • Imprimir
  • Correo electrónico

This year at the Moodle Research Conference in Sousse, Tunisia they hope run some research workshops that will bring together groups of researchers interested in initiating or continuing collaborative research projects. The goal of the workshops are typically publication of papers, although they hope they may lead to other things, such as

...
Leer más...

Integration, exposed: Integration round 2013-08-02 - easy as mate

Detalles
Publicado el 01 Agosto 2013
Categoría: Planeta Moodle
  • Imprimir
  • Correo electrónico
by Sam Hemelryk.  

Cold numbers:

37 issues have been successfully integrated with 2 rejected and 0 delayed. That is a hug 95% success rate, good job everyone!

Hot topics:
  • MDL-39814 - Course activity and resource editing icons are now displayed within a drop down menu with larger icons.
  • MDL-11270 - MSSQL no longer uses ntext instead using nvarchar(max).
  • M
...
Leer más...

Más artículos...

  1. Gavin Henrick: Moodle Add-ons available on Kindle and iTunes
  2. Integration, exposed: Integration round 2013-07-26 - Eventful week
  3. Gavin Henrick: Copyright licensing and files for use in E-Learning
  4. Gavin Henrick: Some thoughts on Licensing – or a License Smoothie
  5. Integration, exposed: Integration round 2013-07-19 - Deprecation week (again)
  6. Integration, exposed: Integration round 2013-07-12 - last one standing
  7. Gavin Henrick: One approach for Group Project Grading
  8. Integration, exposed: Integration round 2013-07-04 - smooth as silk
  9. Tim Hunt: Assessment in Higher Education conference 2013
  10. Tim Hunt: Open University question types ready for Moodle 2.5
  11. Integration, exposed: Integration round 2013-06-27 - light like gold
  12. Gavin Henrick: Upcoming Moodlemoots
  13. Jenny Gray: Seeking an AV delivery system
  14. Tim Hunt: Book review: Computer Aided Assessment of Mathematics by Chris Sangwin
  15. Integration, exposed: Integration round 2013-06-21 - Hi NSA!
  16. Gavin Henrick: Review of the Bigbluebutton LTI integration with Moodle
  17. Gavin Henrick: Moodle Research Conference – Submissions deadline 17th June
  18. Integration, exposed: Integration round 2013-06-14 - Welcome new 2.6 features
  19. Gavin Henrick: Edtech 2013 Presentations
  20. Integration, exposed: Integration round 2013-06-06 - Less drama than Game of Thrones

Página 10 de 58

  • Inicio
  • Anterior
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • Siguiente
  • Final
  • Home
  • Blog
  • Noticias
  • Todas las Noticias

Moodle-Chile.cl is not affiliated with or endorsed by the Moodle Project.

Powered by TILATAM S.A.