PT-2017-7047 · Edx · Edx-Platform
Publicado
2017-03-13
·
Atualizado
2020-01-07
·
CVE-2015-6671
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
edx-platform versions prior to 2015-08-25
Description
The issue allows context-dependent attackers to obtain sensitive information by leveraging access to a database backup, as the database is used for storage of SAML SSO secrets.
Recommendations
For versions prior to 2015-08-25, update to a version that does not require the use of the database for storage of SAML SSO secrets to mitigate the risk of sensitive information disclosure.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Edx-Platform