diff --git a/general/releases/4.5/4.5.14.md b/general/releases/4.5/4.5.14.md index ba6ceb759..8a8382b22 100644 --- a/general/releases/4.5/4.5.14.md +++ b/general/releases/4.5/4.5.14.md @@ -29,4 +29,8 @@ import { ReleaseNoteIntro } from '@site/src/components/ReleaseInformation'; ## Security fixes {/* #security-fixes */} -A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version. +{/* */} + +- [MSA-26-0042](https://moodle.org/mod/forum/discuss.php?d=482607) - Blind SQL injection risk in profile availability condition check +- [MSA-26-0043](https://moodle.org/mod/forum/discuss.php?d=482608) - Possible to bypass the login notification mechanism +{/* */} diff --git a/general/releases/5.0/5.0.10.md b/general/releases/5.0/5.0.10.md index f82b1eb48..8db14476b 100644 --- a/general/releases/5.0/5.0.10.md +++ b/general/releases/5.0/5.0.10.md @@ -21,4 +21,8 @@ import { ReleaseNoteIntro } from '@site/src/components/ReleaseInformation'; ## Security fixes {/* #security-fixes */} -A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version. +{/* */} + +- [MSA-26-0042](https://moodle.org/mod/forum/discuss.php?d=482607) - Blind SQL injection risk in profile availability condition check +- [MSA-26-0043](https://moodle.org/mod/forum/discuss.php?d=482608) - Possible to bypass the login notification mechanism +{/* */} diff --git a/general/releases/5.1/5.1.7.md b/general/releases/5.1/5.1.7.md index 5b4ff645c..30a40c61b 100644 --- a/general/releases/5.1/5.1.7.md +++ b/general/releases/5.1/5.1.7.md @@ -60,4 +60,8 @@ If your site has been upgraded to 5.1.6, please upgrade to 5.1.7 as soon as poss ## Security fixes {/* #security-fixes */} -A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version. +{/* */} + +- [MSA-26-0042](https://moodle.org/mod/forum/discuss.php?d=482607) - Blind SQL injection risk in profile availability condition check +- [MSA-26-0043](https://moodle.org/mod/forum/discuss.php?d=482608) - Possible to bypass the login notification mechanism +{/* */} diff --git a/general/releases/5.2/5.2.3.md b/general/releases/5.2/5.2.3.md index 7531e23c4..ae724398a 100644 --- a/general/releases/5.2/5.2.3.md +++ b/general/releases/5.2/5.2.3.md @@ -63,4 +63,8 @@ If your site has been upgraded to 5.2.2, please upgrade to 5.2.3 as soon as poss ## Security fixes {/* #security-fixes */} -A number of security related issues were resolved. Details of these issues will be released after a period of approximately one week to allow system administrators to safely update to the latest version. +{/* */} + +- [MSA-26-0042](https://moodle.org/mod/forum/discuss.php?d=482607) - Blind SQL injection risk in profile availability condition check +- [MSA-26-0043](https://moodle.org/mod/forum/discuss.php?d=482608) - Possible to bypass the login notification mechanism +{/* */}