Forums | Mahara Community

Security Announcements /
Security issue relating to logging of passwords from Mahara Mobile


Kristina Hoeppner's profile picture
Posts: 3366

10 February 2017, 7:23 PM

Hello,

Pawel Kubzdyl uncovered an issue in Mahara Mobile that logged passwords in plain text to the Mahara access log. This has been fixed for Android: https://play.google.com/store/apps/details?id=org.mahara.mobile Please install version 1.2.1 of Mahara Mobile as soon as possible.

The fix for iOS devices is currently under review by Apple and will be provided as soon as possible.

Cheers

Kristina

 

Kristina Hoeppner's profile picture
Posts: 3366

12 February 2017, 4:55 PM

Hello,

The iOS version of Mahara Mobile that fixes the security issue is now also available. You can access it at https://itunes.apple.com/us/app/mahara-mobile/id1172638950?mt=8

It's called version 1.1.2, but really is 1.2.1 as for Android. The upload process is a bit baffling and I couldn't delete that old pending version and only upload a new build. Next time they should be in sync again.

Cheers

Kristina

 

2 results