Forums | Mahara Community
Security Announcements
/
Security issue relating to the third-party library SimpleSAMLPHP <18.10.5, <19.04.4, <19.10.2
04 March 2020, 18:51
Two security issues have been resolved for SimpleSAMLPHP that relate to information disclosure and log injection. A third one, relating to cross-site scripting in error reports, is also fixed by the latest update:
- Information disclosure (Severity: Low)
- Log injection (Severity: Low)
- Cross-site scripting in error reports (Severity: Low)
All supported versions of Mahara now use SimpleSAMLPHP 1.18.4.
Get the latest releases from our Git repository. You can also download them from Launchpad: