JARVIS Server

Moodle 5.2.3, 5.1.7, 5.0.10 and 4.5.14 are now available (unscheduled release)

Mail detail

Moodle 5.2.3, 5.1.7, 5.0.10 and 4.5.14 are now available (unscheduled release)

securityalerts@moodle.org

Unread normal No attachments

Alleen lezen. Acties komen later.

Back to mail · Open API detail

Metadata

Mail id
1a0a18101914729f
Thread id
1a0a18101914729f
History id
1566948
Received
2026-09-14 21:59 CEST
Sync timestamp
Source
gmail
Importance
normal
Read
no
UNREADCATEGORY_UPDATESINBOX

Body preview

https://lists.moodle.org/w/QK8IylgjJd5VDfG7snO2ZQ/tq0lNDXhoqeaSOSsRiZOjA/ibShbBqebaKdaApQOnyNaQ

To all registered Moodle Administrators,

*Unscheduled Minor Version Release*

I'm writing today to let you know that Moodle LMS 5.2.3, 5.1.7, 5.0.10 and 4.5.14 are now available via the usual open download channels; https://lists.moodle.org/l/QK8IylgjJd5VDfG7snO2ZQ/qLoEliGVXR4nJDasCXjYRw/ibShbBqebaKdaApQOnyNaQ and Git. The release notes for each version can be found at the following links:

Moodle LMS 5.2.3 release notes: https://lists.moodle.org/l/QK8IylgjJd5VDfG7snO2ZQ/2Fvo8GZ18929MkM30sBZ8Alw/ibShbBqebaKdaApQOnyNaQ
Moodle LMS 5.1.7 release notes: https://lists.moodle.org/l/QK8IylgjJd5VDfG7snO2ZQ/7892K0pdakn0nXD7MGeXvpFA/ibShbBqebaKdaApQOnyNaQ
Moodle LMS 5.0.10 release notes: https://lists.moodle.org/l/QK8IylgjJd5VDfG7snO2ZQ/K4N6pTUl01mOZtHR4fmUNQ/ibShbBqebaKdaApQOnyNaQ
Moodle LMS 4.5.14 release notes: https://lists.moodle.org/l/QK8IylgjJd5VDfG7snO2ZQ/7Bqqi1763MFbYCzHAfrI76jA/ibShbBqebaKdaApQOnyNaQ

As mentioned in my "Recent grade penalty calculation fix" email of 28 August, we recommended sites avoid upgrading to versions 5.2.2 or 5.1.6, due to those versions including a fix to gradebook calculations (https://lists.moodle.org/l/QK8IylgjJd5VDfG7snO2ZQ/MhNTOmDfvAKY5FH0M9OzlQ/ibShbBqebaKdaApQOnyNaQ) which did not implement the necessary gradebook calculation freezing process (https://lists.moodle.org/l/QK8IylgjJd5VDfG7snO2ZQ/C1J8921Sr0t5FSOkM94kPA6w/ibShbBqebaKdaApQOnyNaQ). The impact in those versions being that grades calculated using a multiplicator/offset were not frozen to prevent their values possibly changing if a grade re-calculation was triggered in the course (which can sometimes happen automatically). For more details about the issue, please see the associated gradebook forum post (https://lists.moodle.org/l/QK8IylgjJd5VDfG7snO2ZQ/TbNPhh2CzupqgnBPvB763UTg/ibShbBqebaKdaApQOnyNaQ), which contains the same details as the original email.

The fix for that issue has now been finalised in https://lists.moodle.org/l/QK8IylgjJd5VDfG7snO2ZQ/UVHC0DN2Kij2YfVw5g21XQ/ibShbBqebaKdaApQOnyNaQ and is included in today's releases of 5.2.3 and 5.1.7.

*If you upgraded to 5.2.2 or 5.1.6*

If you have already upgraded to 5.2.2 or 5.1.6, please upgrade to 5.2.3 or 5.1.7 as soon as possible. This will help minimise the impact of the above issue and allow you to preserve affected grades (using the old calculation method) if necessary.
Once your site is upgraded, the affected grades will be correctly frozen (so it is possible to decide whether the new calculation method should apply when a re-grade takes place, but old grades can still be maintained). If any affected assignment grades may have already been recalculated since you upgraded to 5.2.2 or 5.1.6, they will be frozen, but with the already changed grade. They can be repaired (returned to their originally calculated value) by triggering a re-grade in the affected course(s) while they remain frozen (they are frozen if nobody has clicked the "Accept grade changes and fix calculation errors" button in the gradebook). One of the easiest ways to achieve this is by temporarily adding a new grade item to the relevant courses. This will initiate an automatic re-grade of grade items in the course when the gradebook is next viewed, with frozen grades using the original calculation method. Once completed, you can remove that temporary grade item.

*If you did not upgrade to 5.2.2 or 5.1.6 (or are using an older version)*

If you are using a 5.2.x or 5.1.x version older than 5.2.2/5.1.6, it is safe to upgrade directly to 5.2.3 or 5.1.7, where you will benefit from the relevant fixes without the missing grade item freeze (any affected grades will immediately be frozen to ensure they are only re-calculated using the new method if approved to do so).

If you are currently using versions older than 5.1.x (such as 5.0.x or 4.5.x), your site did not receive the original bug fix, so no grade calculation changes were made. We do still recommend you upgrade to the latest relevant version (5.0.10 or 4.5.14) as soon as possible due to other fixes included - see "Security and bug fixes" below for more information.

*If your site is hosted on MoodleCloud*

If your Moodle LMS site is hosted on MoodleCloud (https://moodlecloud.com), you were not affected by the missing grade item freeze (MDL-89497). Our team will perform the necessary update soon, which will mean the relevant grade penalty calculation fix will be applied along with the correct freeze procedure, and you will also receive the latest security and bug fixes. No further action is required by you.

*Security and bug fixes*
Due to the nature of our release process, all security and bug fixes that have been completed since our previous minor release are included in today's release, which is why all security supported versions receive an update today. Today's release includes two security fixes, which are listed at the end of this email. As a registered Moodle admin, you receive notice of fixed security issues before they are published more widely. In approximately one week, the details will also be available from https://lists.moodle.org/l/QK8IylgjJd5VDfG7snO2ZQ/Yq3dpkfssY5tFl9sM10FMw/ibShbBqebaKdaApQOnyNaQ. Until those announcements are published next week, please do not publicly disclose information about the security issues (such as posting about them in a forum discussion). This helps ensure you and other registered Moodle admins have time to apply the fixes to their systems before the information is publicly announced.

This minor release does not affect the schedule for the upcoming 5 October major/minor releases.

Kind regards,

Michael Hawkins
Product Manager - Community Contributions
Moodle HQ

==============================================================================
Security Fixes
==============================================================================
MSA-26-0042: Blind SQL injection risk in profile availability condition check

Description:       Insufficient validation of a profile availability condition
                   check resulted in a blind SQL injection risk being
                   available to teachers (and other privileged users such as
                   admins).
Issue summary:     Blind SQL injection risk in profile availability condition
                   check
Severity/Risk:     Serious
Versions affected: 5.2 to 5.2.2, 5.1 to 5.1.6, 5.0 to 5.0.9, 4.5 to 4.5.13 and
                   earlier unsupported versions
Versions fixed:    5.2.3, 5.1.7, 5.0.10 and 4.5.14
Reported by:       Vincent Schneider
Issue no.:         MDL-89484
CVE identifier:    Pending
Changes (5.2):     https://github.com/moodle/moodle/commit/bcac4c2a4a5e51209bb5241be8dd515ccf5b1e3b

==============================================================================
MSA-26-0043: Possible to bypass the login notification mechanism

Description:       It was possible to bypass the login notification mechanism,
                   so a user would not be notified if their account received a
                   new login. This could make it easier for unauthorised users
                   to log in without detection. Note: Valid login credentials
                   (such as username and password) were still required.
Issue summary:     Possible to bypass the login notification mechanism
Severity/Risk:     Minor
Versions affected: 5.2 to 5.2.2, 5.1 to 5.1.6, 5.0 to 5.0.9, 4.5 to 4.5.13 and
                   earlier unsupported versions
Versions fixed:    5.2.3, 5.1.7, 5.0.10 and 4.5.14
Reported by:       Brendan Heywood
Issue no.:         MDL-87817
CVE identifier:    Pending
Changes (5.2):     https://github.com/moodle/moodle/commit/0620afc39b2a75e78dca7011bad0ae4fcb6cbfdb
                   https://github.com/moodle/moodle/commit/46f1fb069634e4410bc9057ce6c7cd24e5fd41ff
==============================================================================


You are receiving this email because you asked for Moodle security news when you registered a Moodle site. If you no longer wish to receive these emails, please re-register your site with your new preferences or use the unsubscribe link below. Note that this inbox is unmonitored, so replies to this email will not be read.

Link to unsubscribe: https://lists.moodle.org/unsubscribe/bXTqEtsi3kWFxAdkLpd763xS9j44lW2rbEg88pa815MRc/tq0lNDXhoqeaSOSsRiZOjA/ibShbBqebaKdaApQOnyNaQ

Recipients

onno.hardebol@gmail.com

CC

No CC

Attachments

No attachment metadata available.