Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET requests to arbitrary domains.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.tenable.com/security/research/tra-2020-49 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-08-04T08:39:25.766Z
Reserved: 2020-01-06T00:00:00
Link: CVE-2020-5775
No data.
Status : Modified
Published: 2020-08-21T18:15:11.847
Modified: 2024-11-21T05:34:34.767
Link: CVE-2020-5775
No data.
OpenCVE Enrichment
No data.
Weaknesses