Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call endpoints exceeding their access. This vulnerability has been patched in commit 019888f.
Metrics
Affected Vendors & Products
References
History
Thu, 24 Oct 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Openedx
Openedx edx-platform |
|
CPEs | cpe:2.3:a:openedx:edx-platform:*:*:*:*:*:*:*:* | |
Vendors & Products |
Openedx
Openedx edx-platform |
|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-01-13T07:40:44.052Z
Updated: 2024-10-24T15:08:35.807Z
Reserved: 2024-01-08T04:59:27.374Z
Link: CVE-2024-22209
Vulnrichment
Updated: 2024-08-01T22:35:34.932Z
NVD
Status : Modified
Published: 2024-01-13T08:15:07.557
Modified: 2024-11-21T08:55:48.293
Link: CVE-2024-22209
Redhat
No data.