<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>Security Announcements</title>
    <link>http://moodle.org/mod/forum/view.php?f=996</link>
    <description> 

Moodle Security Procedures
We treat security issues in Moodle software very seriously. Even though we dedicate a lot of time designing our code to avoid such problems, it is inevitable in a project of this size that new vulnerabilities will occasionally be discovered.
We practice responsible disclosure, which means we have a policy of disclosing all security issues that come to our attention, but only after we have solved the issue and given registered Moodle sites some time to upgrade or patch their installations.
We welcome reports of security issues and will work with reporters to fix problems and publicise patches to Moodle users as quickly as possible.

How can I report a security issue?
Please &quot;Create a new issue&quot; in the Moodle Tracker describing the problem (and solution if possible) in detail. Make sure you set the Security Level accurately to make sure that the security team sees it. Bugs classified as a &quot;Serious security issue&quot; will be hidden from the general public until the security team (led by Petr Skoda) is able to resolve it and publish fixes to registered Moodle sites (see below).
How can I keep my site secure?
It's good practice to always use the latest stable release of the version you are using. It is very safe to upgrade from 1.9.6 to 1.9.7+, for example, at any time. CVS is a very easy way to do this.
How can I keep track of recent security issues?

Register your Moodle sites with moodle.org (visit admin/index.php in your installation to see the registration button), making sure to enable the option of being notified about security issues and updates. After your registration is accepted, your email address will be automatically added to our low-volume securityalerts mailing list.
Eventually, all important security issues are published to the general public via the forum on this page. You can subscribe to the RSS feed on this page to automatically add new issues in your favourite feed reader or portal. (Please note that security alerts prior to 2008 were made on a different site and do not appear here.) You can also follow moodlesecurity on Twitter. 

See also

Security documentation
Security FAQ

</description>
    <generator>Moodle</generator>
    <language>en</language>
    <copyright>&amp;#169; 2012 Moodle.org</copyright>
    <image>
      <url>http://moodle.org/theme/image.php?theme=moodleofficial&amp;amp;image=i%2Frsssitelogo&amp;amp;rev=676</url>
      <title>moodle</title>
      <link>http://moodle.org</link>
      <width>140</width>
      <height>35</height>
    </image>
    <item>
      <title>MSA-12-0023: External enrolment plugin context check issue</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=198632&amp;parent=865988</link>
      <pubDate>Mon, 19 Mar 2012 05:57:57 GMT</pubDate>
      <description>by Michael de Raadt. &amp;nbsp;&lt;p&gt;&lt;table&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Topic:&lt;/td&gt;
&lt;td&gt;/enrol/externallib.php method core_enrol_external .get_enrolled_users() uses undefined $context and $coursecontext's in 3 has_capability() calls&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Severity:&lt;/td&gt;
&lt;td&gt;Major&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Versions affected:&lt;/td&gt;
&lt;td&gt;2.2 to 2.2.1+&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Reported by:&lt;/td&gt;
&lt;td&gt;Petr Škoda&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Issue no.:&lt;/td&gt;
&lt;td&gt;&lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-31178&quot;&gt;MDL-31178&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p&gt;CVE Identifier:&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;CVE-2012-1170&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Changes (master):&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;http://git.moodle.org/gw?p=moodle.git&amp;amp;a=search&amp;amp;h=HEAD&amp;amp;st=commit&amp;amp;s=MDL-31178&quot; class=&quot;_blanktarget&quot;&gt;http://git.moodle.org/gw?p=moodle.git&amp;amp;a=search&amp;amp;h=HEAD&amp;amp;st=commit&amp;amp;s=MDL-31178&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Capability checks in the external enrolment plugin were not being performed thoroughly enough.&lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=198632&amp;parent=865988</guid>
    </item>
    <item>
      <title>MSA-12-0022: Security conflict in Web services</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=198631&amp;parent=865987</link>
      <pubDate>Mon, 19 Mar 2012 05:56:19 GMT</pubDate>
      <description>by Michael de Raadt. &amp;nbsp;&lt;p&gt;&lt;table&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Topic:&lt;/td&gt;
&lt;td&gt;HTML5 apps cannot call Web services functions if an HTTP resource is retrieved from the Moodle installation&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Severity:&lt;/td&gt;
&lt;td&gt;Minor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Versions affected:&lt;/td&gt;
&lt;td&gt;2.2 to 2.2.1+, 2.1 to 2.1.4+&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Reported by:&lt;/td&gt;
&lt;td&gt;Juan Leyva&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p&gt;Workaround:&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;Disable Web services&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Issue no.:&lt;/td&gt;
&lt;td&gt;&lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-30495&quot;&gt;MDL-30495&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Changes (master):&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;http://git.moodle.org/gw?p=moodle.git&amp;amp;a=search&amp;amp;h=HEAD&amp;amp;st=commit&amp;amp;s=MDL-30495&quot; class=&quot;_blanktarget&quot;&gt;http://git.moodle.org/gw?p=moodle.git&amp;amp;a=search&amp;amp;h=HEAD&amp;amp;st=commit&amp;amp;s=MDL-30495&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;HTML5 apps were being sent cookies which, when sent in later access requests, would cause the Web services to block them.&lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=198631&amp;parent=865987</guid>
    </item>
    <item>
      <title>MSA-12-0021: Course information leak through tags</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=198630&amp;parent=865986</link>
      <pubDate>Mon, 19 Mar 2012 05:54:42 GMT</pubDate>
      <description>by Michael de Raadt. &amp;nbsp;&lt;p&gt;&lt;table&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Topic:&lt;/td&gt;
&lt;td&gt;Adding Tag to an unavailable course makes it visible to students&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Severity:&lt;/td&gt;
&lt;td&gt;Minor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Versions affected:&lt;/td&gt;
&lt;td&gt;2.2 to 2.2.1+, 2.1 to 2.1.4+&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Reported by:&lt;/td&gt;
&lt;td&gt;Ivo Šmelhaus&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p&gt;Workaround:&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;Don't enable block_tags_showcoursetags&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Issue no.:&lt;/td&gt;
&lt;td&gt;&lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-31466&quot;&gt;MDL-31466&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p&gt;CVE Identifier:&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;CVE-2012-1161&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Changes (master):&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;http://git.moodle.org/gw?p=moodle.git&amp;amp;a=search&amp;amp;h=HEAD&amp;amp;st=commit&amp;amp;s=MDL-31466&quot; class=&quot;_blanktarget&quot;&gt;http://git.moodle.org/gw?p=moodle.git&amp;amp;a=search&amp;amp;h=HEAD&amp;amp;st=commit&amp;amp;s=MDL-31466&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Courses identifiable by tags were being displayed in a tag search even when the courses were hidden.&lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=198630&amp;parent=865986</guid>
    </item>
    <item>
      <title>MSA-12-0020: Forum subscription permission issue</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=198629&amp;parent=865985</link>
      <pubDate>Mon, 19 Mar 2012 05:53:22 GMT</pubDate>
      <description>by Michael de Raadt. &amp;nbsp;&lt;p&gt;&lt;table&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Topic:&lt;/td&gt;
&lt;td&gt;Not enrolled users (admins...) are able to subscribe/unsubscribe themselves via mod/forum/index.php&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Severity:&lt;/td&gt;
&lt;td&gt;Minor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Versions affected:&lt;/td&gt;
&lt;td&gt;2.2 to 2.2.1+, 2.1 to 2.1.4+&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Reported by:&lt;/td&gt;
&lt;td&gt;Eloy Lafuente&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Issue no.:&lt;/td&gt;
&lt;td&gt;&lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-31426&quot;&gt;MDL-31426&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p&gt;CVE Identifier:&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;CVE-2012-1160&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Changes (master):&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;http://git.moodle.org/gw?p=moodle.git&amp;amp;a=search&amp;amp;h=HEAD&amp;amp;st=commit&amp;amp;s=MDL-31426&quot; class=&quot;_blanktarget&quot;&gt;http://git.moodle.org/gw?p=moodle.git&amp;amp;a=search&amp;amp;h=HEAD&amp;amp;st=commit&amp;amp;s=MDL-31426&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Administrators and managers were able to subscribe to forums in courses they were not involved in without a permission check.&lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=198629&amp;parent=865985</guid>
    </item>
    <item>
      <title>MSA-12-0019: Overview report and hidden course issue</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=198628&amp;parent=865984</link>
      <pubDate>Mon, 19 Mar 2012 05:51:35 GMT</pubDate>
      <description>by Michael de Raadt. &amp;nbsp;&lt;p&gt;&lt;table&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Topic:&lt;/td&gt;
&lt;td&gt;Overview report shows hidden courses&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Severity:&lt;/td&gt;
&lt;td&gt;Minor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Versions affected:&lt;/td&gt;
&lt;td&gt;2.2 to 2.2.1+, 2.1 to 2.1.4+&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Reported by:&lt;/td&gt;
&lt;td&gt;Mark Nelson&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Issue no.:&lt;/td&gt;
&lt;td&gt;&lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-29892&quot;&gt;MDL-29892&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p&gt;CVE Identifier:&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;CVE-2012-1159&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Changes (master):&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;http://git.moodle.org/gw?p=moodle.git&amp;amp;a=search&amp;amp;h=HEAD&amp;amp;st=commit&amp;amp;s=MDL-29892&quot; class=&quot;_blanktarget&quot;&gt;http://git.moodle.org/gw?p=moodle.git&amp;amp;a=search&amp;amp;h=HEAD&amp;amp;st=commit&amp;amp;s=MDL-29892&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Users unable to see hidden courses were able to see them in the overview report.&lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=198628&amp;parent=865984</guid>
    </item>
    <item>
      <title>MSA-12-0018: Course information leak in Gradebook export</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=198627&amp;parent=865983</link>
      <pubDate>Mon, 19 Mar 2012 05:49:33 GMT</pubDate>
      <description>by Michael de Raadt. &amp;nbsp;&lt;p&gt;&lt;table&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Topic:&lt;/td&gt;
&lt;td&gt;Gradeboook export allows role that cannot see hidden grades to export all grade and hidden is viewable&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Severity:&lt;/td&gt;
&lt;td&gt;Minor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Versions affected:&lt;/td&gt;
&lt;td&gt;2.2 to 2.2.1+, 2.1 to 2.1.4+&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Reported by:&lt;/td&gt;
&lt;td&gt;Kathryn Fortin&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Issue no.:&lt;/td&gt;
&lt;td&gt;&lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-29080&quot;&gt;MDL-29080&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p&gt;CVE Identifier:&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;CVE-2012-1158&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Changes (master):&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;http://git.moodle.org/gw?p=moodle.git&amp;amp;a=search&amp;amp;h=HEAD&amp;amp;st=commit&amp;amp;s=MDL-29080&quot; class=&quot;_blanktarget&quot;&gt;http://git.moodle.org/gw?p=moodle.git&amp;amp;a=search&amp;amp;h=HEAD&amp;amp;st=commit&amp;amp;s=MDL-29080&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Users unable to see hidden grade items were able to view this information in an export.&lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=198627&amp;parent=865983</guid>
    </item>
    <item>
      <title>MSA-12-0017: Personal information leak issue</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=198625&amp;parent=865980</link>
      <pubDate>Mon, 19 Mar 2012 05:47:08 GMT</pubDate>
      <description>by Michael de Raadt. &amp;nbsp;&lt;p&gt;&lt;table&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Topic:&lt;/td&gt;
&lt;td&gt;'Full name format' set to 'First name' within 'Site Policies', but breadcrumbs show First + Last Name.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Severity:&lt;/td&gt;
&lt;td&gt;Minor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Versions affected:&lt;/td&gt;
&lt;td&gt;2.2 to 2.2.1+, 2.1 to 2.1.4+, 2.0 to 2.0.7+&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Reported by:&lt;/td&gt;
&lt;td&gt;John Fitchett&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p&gt;Workaround:&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;Use lang file based full-name display&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Issue no.:&lt;/td&gt;
&lt;td&gt;&lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-31463&quot;&gt;MDL-31463&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p&gt;CVE Identifier:&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;CVE-2012-1169&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Changes (master):&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;http://git.moodle.org/gw?p=moodle.git&amp;amp;a=search&amp;amp;h=HEAD&amp;amp;st=commit&amp;amp;s=MDL-31463&quot; class=&quot;_blanktarget&quot;&gt;http://git.moodle.org/gw?p=moodle.git&amp;amp;a=search&amp;amp;h=HEAD&amp;amp;st=commit&amp;amp;s=MDL-31463&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;When the administrative setting to display users' names was set to first name only, users' full names were still appearing in page breadcrumbs.&lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=198625&amp;parent=865980</guid>
    </item>
    <item>
      <title>MSA-12-0016: Default repository capabilities issue</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=198624&amp;parent=865979</link>
      <pubDate>Mon, 19 Mar 2012 05:45:19 GMT</pubDate>
      <description>by Michael de Raadt. &amp;nbsp;&lt;p&gt;&lt;table&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Topic:&lt;/td&gt;
&lt;td&gt;authenticated user &quot;view&quot; capability set to &quot;allow&quot; for all repos&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Severity:&lt;/td&gt;
&lt;td&gt;Minor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Versions affected:&lt;/td&gt;
&lt;td&gt;2.2 to 2.2.1+, 2.1 to 2.1.4+, 2.0 to 2.0.7+&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Reported by:&lt;/td&gt;
&lt;td&gt;Andrea Bicciolo&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p&gt;Workaround:&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;Manually change capability for repositories&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Issue no.:&lt;/td&gt;
&lt;td&gt;&lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-30452&quot;&gt;MDL-30452&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p&gt;CVE Identifier:&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;CVE-2012-1157&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Changes (master):&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;http://git.moodle.org/gw?p=moodle.git;a=commit;h=246c2cb8e5af71a7d7c605b8fc9f9563e0fb3bc4&quot; class=&quot;_blanktarget&quot;&gt;http://git.moodle.org/gw?p=moodle.git;a=commit;h=246c2cb8e5af71a7d7c605b8fc9f9563e0fb3bc4&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Not all repositories are intended for student use, however all repositories were viewable by all users by default. This change will affect new installations only. Existing site admins should review their repository capabilities.&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=198624&amp;parent=865979</guid>
    </item>
    <item>
      <title>MSA-12-0015: Backup and private files issue</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=198623&amp;parent=865978</link>
      <pubDate>Mon, 19 Mar 2012 05:42:36 GMT</pubDate>
      <description>by Michael de Raadt. &amp;nbsp;&lt;p&gt;&lt;table&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Topic:&lt;/td&gt;
&lt;td&gt;Backup with user files includes users' private files&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Severity:&lt;/td&gt;
&lt;td&gt;Minor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Versions affected:&lt;/td&gt;
&lt;td&gt;2.2 to 2.2.1+, 2.1 to 2.1.4+, 2.0 to 2.0.7+&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Reported by:&lt;/td&gt;
&lt;td&gt;Ralf Hilgenstock&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p&gt;Workaround:&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;Disable private files&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Issue no.:&lt;/td&gt;
&lt;td&gt;&lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-29248&quot;&gt;MDL-29248&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p&gt;CVE Identifier:&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;CVE-2012-1156&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Changes (master):&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;http://git.moodle.org/gw?p=moodle.git&amp;amp;a=search&amp;amp;h=HEAD&amp;amp;st=commit&amp;amp;s=MDL-29248&quot; class=&quot;_blanktarget&quot;&gt;http://git.moodle.org/gw?p=moodle.git&amp;amp;a=search&amp;amp;h=HEAD&amp;amp;st=commit&amp;amp;s=MDL-29248&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Course backups were including users' private files unnecessarily.&lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=198623&amp;parent=865978</guid>
    </item>
    <item>
      <title>MSA-12-0014: Password and Web services issue</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=198622&amp;parent=865977</link>
      <pubDate>Mon, 19 Mar 2012 05:41:16 GMT</pubDate>
      <description>by Michael de Raadt. &amp;nbsp;&lt;p&gt;&lt;table&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Topic:&lt;/td&gt;
&lt;td&gt;core_user_update_users user password is reset if not specified&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Severity:&lt;/td&gt;
&lt;td&gt;Minor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Versions affected:&lt;/td&gt;
&lt;td&gt;2.2 to 2.2.1+, 2.1 to 2.1.4+, 2.0 to 2.0.7+&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Reported by:&lt;/td&gt;
&lt;td&gt;Fábio Souto&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p&gt;Workaround:&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;Turn off web services&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Issue no.:&lt;/td&gt;
&lt;td&gt;&lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-30878&quot;&gt;MDL-30878&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p&gt;CVE Identifier:&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;CVE-2012-1168&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Changes (master):&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;http://git.moodle.org/gw?p=moodle.git&amp;amp;a=search&amp;amp;h=HEAD&amp;amp;st=commit&amp;amp;s=MDL-30878&quot; class=&quot;_blanktarget&quot;&gt;http://git.moodle.org/gw?p=moodle.git&amp;amp;a=search&amp;amp;h=HEAD&amp;amp;st=commit&amp;amp;s=MDL-30878&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;A Web service function for updating user profiles was resetting user passwords when they were not supplied with update information.&lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=198622&amp;parent=865977</guid>
    </item>
  </channel>
</rss>
