Forums | Mahara Community
Security Announcements
/
XXE-vulnerability in SimpleSamlPHP before Mahara 24.04.8
05 December 2024, 18:19
Hello,
This latest release contains one security fix that was classed as 'high risk' from the SimpleSamlPHP project. A list of fixes is available on the 'Releases' page, accessible to subscribers.
Subscribers have two options for accessing the latest code.
Via Git: 24.04 Git branch
As downloadable package
The changes are also available on the 'Releases' page as downloadable packages under the heading 'Mahara download files...' in each respective release, which also includes a list of issues linked to their descriptions that have been fixed:
If you use the download files, make sure not to download a file called 'source code'. You want to download the files that have the compiled code as only that will come with all necessary libraries and stylesheet information.
Update information
Please see the wiki for information on updating Mahara, based on the method you use, either via the code repository (Git) or the downloadable package.
As subscriber, we recommend you update your instance of Mahara to the latest maintenance release of of Mahara 24.04.
Thank you
The Mahara team at Catalyst