MSA-11-0030: Box.net repository integration authentication issue

MSA-11-0030: Box.net repository integration authentication issue

by Michael de Raadt -
Number of replies: 0
Topic: Box.net repository has security flaws
Severity: Serious
Versions affected: < 2.1.2, < 2.0.5 (1.9.x not affected)
Reported by: Alex Willen
Issue no.: MDL-27289
Solution: upgrade to latest version
Changes (master): http://git.moodle.org/gw?p=moodle.git;a=commit;h=3deff6c9d2bb4ab3144b3ca7b93d6a2ef6a87af2
Workaround: Disable the Box.net repository

Description:

The Box.net plugin was created before Box.net released an OAuth-like authentication, which requires a user to enter their username and password in moodle site.