PT-2017-7047 · Edx · Edx-Platform

Published

2017-03-13

·

Updated

2020-01-07

·

CVE-2015-6671

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions edx-platform versions prior to 2015-08-25
Description The issue allows context-dependent attackers to obtain sensitive information by leveraging access to a database backup, as the database is used for storage of SAML SSO secrets.
Recommendations For versions prior to 2015-08-25, update to a version that does not require the use of the database for storage of SAML SSO secrets to mitigate the risk of sensitive information disclosure.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-6671

Affected Products

Edx-Platform