MSA-11-0018: Lacking capability controls over cohorts

MSA-11-0018: Lacking capability controls over cohorts

by Michael de Raadt -
Number of replies: 0
Topic: Cohort enrol plugin capability problems and missing cohort access control
Severity: Minor
Versions affected: < 2.0.4, < 2.1.1 (1.9.x not affected)
Reported by: Petr Škoda
Issue no.:

MDL-28432

Solution: upgrade to 2.0.4 or 2.1.1
Workaround: avoid using cohorts

Description:

In order to securely control the creation and oversight of cohorts, additional capabilities have been introduced.