Impact
The vulnerability is a path traversal flaw that allows a user with course import privileges to craft an archive that resolves outside the intended course staging directory, enabling them to corrupt files in a sibling staging directory that shares an identical base‑64 prefix. This flaw does not provide arbitrary write or read access to the filesystem, nor does it allow code execution. The potential impact is limited to cross‑tenant file corruption within the import process.
Affected Systems
Affects the Open edX Platform, specifically versions from Aspen.1 up to and including Ulmo and Verawood.1. Users running older releases can submit crafted .tar.gz archives via the import_olx workflow in the cms.djangoapps.contentstore.views.import_export.import_handler endpoint. The issue is mitigated in releases Ulmo and Verawood.1, where the patch corrects the path validation logic.
Risk and Exploitability
With a CVSS score of 4.3, the vulnerability is considered low‑severity. The EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. The typical attack requires a user with import permission, which is a privileged role. Because the flaw only permits limited file corruption and not arbitrary writes or execution, the risk profile remains low, though the ability to overwrite shared staging files could cause operational disruption in multi‑tenant environments.
OpenCVE Enrichment