A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable).
{
"versions": [
{
"introduced": "3.5.0"
},
{
"last_affected": "3.5.8"
},
{
"introduced": "3.6.0"
},
{
"last_affected": "3.6.6"
},
{
"introduced": "3.7.0"
},
{
"last_affected": "3.7.2"
}
]
}