PT-2018-4362 · Edx · Edx Configuration Repo

Publicado

2018-02-03

·

Atualizado

2018-03-02

·

CVE-2015-2186

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions edx Configuration Repo (affected versions not specified)
Description The issue allows remote websites to spoof edX accounts by leveraging the use of the string literal "False" instead of a boolean False for the CORS ORIGIN ALLOW ALL setting.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-2186

Produtos afetados

Edx Configuration Repo