International ILIAS Blog

English-language blog on ILIAS with news and background information

Keyword: Security

Kunkel, Matthias [mkunkel] - 26. Sep 2023, 14:40
Keywords: Security

On 21 June 2023, the ILIAS open source e-Learning e.V. has released an important security update for ILIAS 8 and 7. Among the security fixes mentioned in the release notes[1] [2] there is one that deserves special attention.


[1] https://docu.ilias.de/goto_docu_pg_141711_1719.html
[2] https://docu.ilias.de/goto_docu_pg_141710_1719.html
Comments (0) · Link

Kunkel, Matthias [mkunkel] - 13. Dec 2021, 18:45
Keywords: Security

ILIAS is not affected by the currently reported security problem (CVE-2021-44228) for the library log4j, which is also used by ILIAS. The reason is that we use the older version 1.2.15 in ILIAS, which does not yet have the affected function, see also here.

Comments (0) · Link

Kruse, Fabian [Fabian] - 19. Feb 2019, 10:06
Keywords: ILIAS 6.0, Security, Technical Board, Test&Assessment

Many ILIAS users want to access their LMS from their smartphones. As ILIAS is responsive, it can easily be used on smaller screens. But there are limits to mobile usage. For this reason, the topic "mobile ILIAS" continues to be discussed regularly. One approach that was developed within the ILIAS community is the Pegasus app: Its users get logged in automatically to their ILIAS platform and they can access documents offline. They can also work with position-based augmented reality scenarios. We spoke to technical board member Timon Amstutz about the app and the upcoming ILIAS developments.

Comments (0) · Link

Kruse, Fabian [Fabian], Killing, Alexander [alex] - 16. Dec 2016, 11:56
Keywords: Security, Technical Board

More and more we read in the media about targeted hacks and attacks on popular software platforms, databases and content management systems. Especially software with many users can be a worthwhile target for hackers looking to steal personal information.

As server-operated software, ILIAS is also theoretically vulnerable to such attacks. So that it never comes to that though, we are working hard to prevent bugs and to close security loopholes that become known to us. Together with the technical board, we have put together a small FAQ to explain how security vulnerabilities are dealt with in ILIAS.

Comments (0) · Link

Kruse, Fabian [Fabian] - 12. May 2016, 16:04
Keywords: Security, Technical Board

The Technical Board has received a security list request regarding the latest ImageMagick vulnerabilities with several remote code execution vectors among them. These were announced last week (see: ImageTragick). To exploit these vulnerabilities, an attacker needs nothing more than the possibility to upload infected image files which are supposed to be post-processed by ImageMagick. This is true for each ILIAS user who is able to upload a profile picture or images at a variety of other places. Mitigation of the issue in ILIAS is unfortunately not possible at short notice.

ILIAS administrators should use a policy file as described at the website mentioned above to disable the vulnerable ImageMagick coders. Furthermore, an updated version of ImageMagick has already been released. We strongly recommend upgrading to the latest version to allow for safe operation of your platforms.

Comments (0) · Link