Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call endpoints exceeding their access. This vulnerability has been patched in commit 019888f.
References
Configurations
History
22 Jan 2024, 19:20
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-13 08:15
Updated : 2024-02-05 00:22
NVD link : CVE-2024-22209
Mitre link : CVE-2024-22209
CVE.ORG link : CVE-2024-22209
JSON object : View
Products Affected
edx
- edx-platform
CWE
CWE-284
Improper Access Control