Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call endpoints exceeding their access. This vulnerability has been patched in commit 019888f.
References
Configurations
History
No history.
Information
Published : 2024-01-13 08:15
Updated : 2024-01-22 19:20
NVD link : CVE-2024-22209
Mitre link : CVE-2024-22209
CVE.ORG link : CVE-2024-22209
JSON object : View
Products Affected
edx
- edx-platform
CWE
CWE-284
Improper Access Control