1.9.14 commit for MDL-28615?

Re: 1.9.14 commit for MDL-28615?

by Tim Hunt -
Number of replies: 0
Picture of Core developers Picture of Documentation writers Picture of Particularly helpful Moodlers Picture of Peer reviewers Picture of Plugin developers

No, a fix does not seem to be planned for 1.9.x. The key bit from that link:

"About 19_STABLE.... It seems that you only have rearranged code a bit to be able to print the nopermissions error with everything calculated. I guess you do so to rely on the checks performed by forum_search_posts() so initially I'd say it's ok but perhaps it's too much backporting (and radically different). Nah, let's be conservative, my -1 for 19_STABLE."

So, basically, since the privacy problem was very minor (in some situations you could see some people's names when you were not supposed to be able to) and the only way to fix it involved big and risky changes to the code, they decided it was not appropriate to fix on 1.9.

Who can access security tracker issues of each severity is summarised here: http://docs.moodle.org/dev/Using_Tracker#Tracker_fields

Average of ratings: Useful (2)