Description: The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF. Issue summary: Logout CSRF in admin/tool/mfa/auth.php Severity/Risk: Minor Versions affected: 4.3 to 4.3.3 Versions fixed: 4.3.4 Reported by: Petr Skoda Issue no.: MDL-80877 Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-80877
Created moodle tracking bugs for this issue: Affects: epel-all [bug 2282064] Affects: fedora-all [bug 2282063]