MSA-11-0053: Security and system administration conflict

MSA-11-0053: Security and system administration conflict

by Michael de Raadt -
Number of replies: 0
Topic: CLI cron doesn't work if blockedip used
Severity: Minor
Versions affected: 2.1 to 2.1.2+, 2.0 to 2.0.5+ (1.9.x not affected)
Reported by: Ryan Smith
Issue no.: MDL-29396
Changes (master): http://git.moodle.org/gw?p=moodle.git;a=commit;h=ade30ad3c420ce035a3d68287db701b70e806b3f
Workaround: Avoid CLI or do not rely on IP blocking

Description:

The command line interface for administration was not working when IP blocking was used. Removing blocked IPs allows the CLI to work but reduces security.