MSA-19-0009: get_with_capability_join/get_users_by_capability not aware of context freezing

MSA-19-0009: get_with_capability_join/get_users_by_capability not aware of context freezing

by Michael Hawkins -
Number of replies: 0

get_with_capability_join and get_users_by_capability were not taking context freezing into account when checking user capabilities


Severity/Risk: Minor
Versions affected: 3.6 to 3.6.2
Versions fixed: 3.6.3
Reported by: Andrew Nicols
CVE identifier: CVE-2019-3852
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-64410
Tracker issue: MDL-64410 get_with_capability_join/get_users_by_capability not aware of context freezing