Security announcements

MSA-14-0007: Access issue in Wiki

بواسطة - Michael de Raadt
Description: There were missing access checks on Wiki pages allowing students to see pages of other students' individual wikis.
Issue summary: Students able to see others' Individual wiki through the Recent activity block
Severity/Risk: Serious
Versions affected: 2.6 to 2.6.1, 2.5 to 2.5.4, 2.4 to 2.4.8 and earlier unsupported versions
Versions fixed: 2.6.2, 2.5.5 and 2.4.9
Reported by: Monash University VLE team
Issue nos.: MDL-39990
CVE identifier: CVE-2014-0123
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-39990

MSA-14-0006: Capability issue in Chat

بواسطة - Michael de Raadt
Description: Capabilities to chat were being checked at the start of a chat, but not during, so changes were not effective immediately.
Issue summary: Broken access control vulnerability with /mod/chat/chat_ajax.php
Severity/Risk: Minor
Versions affected: 2.6 to 2.6.1, 2.5 to 2.5.4, 2.4 to 2.4.8 and earlier unsupported versions
Versions fixed: 2.6.2, 2.5.5 and 2.4.9
Reported by: Jun Zhu
Issue nos.: MDL-44082
CVE identifier: CVE-2014-0122
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-44082

MSA-14-0005: Access issue in Feedback activity

بواسطة - Michael de Raadt
Description: It was possible to start a Feedback activity while it was supposed to be closed.
Issue summary: Feedback Availability dates not honored in complete.php
Severity/Risk: Minor
Versions affected: 2.6 to 2.6.1, 2.5 to 2.5.4, 2.4 to 2.4.8 and earlier unsupported versions
Versions fixed: 2.6.2, 2.5.5 and 2.4.9
Reported by: Tomasz Muras
Issue no.: MDL-43656
CVE identifier: CVE-2014-0127
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-43656

MSA-14-0004: Incorrect filtering in Quiz

بواسطة - Michael de Raadt
Description: Question strings were not being filtered correctly possibly allowing cross site scripting.
Issue summary: quiz_question_tostring can cause invalid HTML
Severity/Risk: Minor
Versions affected: 2.6 to 2.6.1, 2.5 to 2.5.4, 2.4 to 2.4.8 and earlier unsupported versions
Versions fixed: 2.6.2, 2.5.5 and 2.4.9
Reported by: Tim Hunt
Issue nos.: MDL-43690, MDL-43846
CVE identifier: CVE-2014-2571
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-43690

MSA-14-0003: Cross-site request forgery vulnerability in profile fields

بواسطة - Michael de Raadt
Description: Custom profile fields and categories were open to deletion without proper session checking.
Issue summary: Two Cross-site Request Forgery(CSRF) vulnerabilities found in /user/profile/index.php
Severity/Risk: Serious
Versions affected: 2.6, 2.5 to 2.5.4, 2.4 to 2.4.7, 2.3 to 2.3.10 and earlier unsupported versions
Versions fixed: 2.6.1, 2.5.4, 2.4.8 and 2.3.11
Reported by: Jun Zhu
Issue no.: MDL-42883
CVE identifier: CVE-2014-0010
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-42883

MSA-14-0002: Group constraints lacking in "login as"

بواسطة - Michael de Raadt
Description: Users were able to log in as a user who in a is not in the same group without the permission to see all groups.
Issue summary: Users with loginas permission and access all groups prohibited can login as user not in their group by direct url
Severity/Risk: Minor
Versions affected: 2.6, 2.5 to 2.5.4, 2.4 to 2.4.7, 2.3 to 2.3.10 and earlier unsupported versions
Versions fixed: 2.6.1, 2.5.4, 2.4.8 and 2.3.11
Reported by: Itamar Tzadok
Issue no.: MDL-42643
CVE identifier: CVE-2014-0009
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-42643

MSA-14-0001: Config passwords visibility issue

بواسطة - Michael de Raadt
Description: Some password changes on admin pages were being recorded and shown to administrators in the config log report.
Issue summary: Config Changes Report reveals passwords as plain text
Severity/Risk: Minor
Versions affected: 2.6, 2.5 to 2.5.4, 2.4 to 2.4.7 and earlier unsupported versions
Versions fixed: 2.6.1, 2.5.4 and 2.4.8
Reported by: Andrew Steele
Issue no.: MDL-36721
CVE identifier: CVE-2014-0008
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-36721

MSA-13-0040: Cross site scripting vulnerability in YUI library

بواسطة - Michael de Raadt
Description: Flash files distributed with the YUI library may have allowed for cross-site scripting attacks. This is additional to MSA-13-0025.
Issue summary: YUI2 security vulnerability
Severity/Risk: Serious
Versions affected: 2.3 to 2.3.9 and earlier unsupported versions
Versions fixed: 2.3.10
Reported by: Petr Škoda
Issue no.: MDL-42780
CVE identifier: CVE-2013-6780
Workaround Remove all SWF files under the lib/yui directory.
Changes (2.3): http://git.moodle.org/gw?p=moodle.git&a=search&h=refs%2Fheads%2FMOODLE_23_STABLE&st=commit&s=MDL-42780

MSA-13-0039: Cross site scripting in Quiz

بواسطة - Michael de Raadt
Description: JavaScript in question answers was being executed on the Quiz Results page.
Issue summary: XSS on view quiz results page
Severity/Risk: Serious
Versions affected: 2.5 to 2.5.2, 2.4 to 2.4.6, 2.3 to 2.3.9 and earlier unsupported versions
Versions fixed: 2.6, 2.5.3, 2.4.7 and 2.3.10
Reported by: Michael Hess
Issue no.: MDL-41820
CVE identifier: CVE-2013-4525
Workaround Disable text-based question types.
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-41820

MSA-13-0038: Access to server files through repository

بواسطة - Michael de Raadt
Description: The file system repository was allowing access to files beyond the Moodle file area.
Issue summary: File System repository gives read access to the whole file system
Severity/Risk: Serious
Versions affected: 2.5 to 2.5.2, 2.4 to 2.4.6, 2.3 to 2.3.9 and earlier unsupported versions
Versions fixed: 2.6, 2.5.3, 2.4.7 and 2.3.10
Reported by: Frédéric Massart
Issue no.: MDL-41807
CVE identifier: CVE-2013-4524
Workaround Do not enable File System repository (default)
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-41807