PT-2017-7047 · Edx · Edx-Platform
Published
2017-03-13
·
Updated
2020-01-07
·
CVE-2015-6671
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
edx-platform versions prior to 2015-08-25
Description
The issue allows context-dependent attackers to obtain sensitive information by leveraging access to a database backup, as the database is used for storage of SAML SSO secrets.
Recommendations
For versions prior to 2015-08-25, update to a version that does not require the use of the database for storage of SAML SSO secrets to mitigate the risk of sensitive information disclosure.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Edx-Platform