Andrew Steele found that some password changes were visible in plain text to Administrators in the config changes report. This issue affected Moodle versions 2.6, 2.5 to 2.5.4, 2.4 to 2.4.7 and earlier unsupported versions. It has been fixed in versions 2.6.1, 2.5.4 and 2.4.8. I have not checked if versions 1.9.19 in EPEL 5 is affected or not. Patch: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-36721
Created moodle tracking bugs for this issue: Affects: fedora-all [bug 1055388] Affects: epel-all [bug 1055390]
Upstream announcement: https://moodle.org/mod/forum/discuss.php?d=252414