-
Bug
-
Resolution: Fixed
-
Minor
-
3.11.5, 4.0
-
MOODLE_311_STABLE, MOODLE_400_STABLE
-
MOODLE_311_STABLE, MOODLE_39_STABLE, MOODLE_400_STABLE, MOODLE_401_STABLE
-
MDL-73610_401 -
A moderated-severity report @ github:
https://github.com/moodle/moodle/security/dependabot (CVE-2021-32796)
has been reported about the xmldom package and it needs to be upgraded to version 0.7.0 (right now using 0.6.0).
For sure this is not critical as far as we only use it as development (component library) requirement, but better get it fixed.