PT-2024-5257 · Amazon · Aws S3
Feanil
·
Published
2024-07-25
·
Updated
2024-07-26
·
CVE-2024-41806
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Open edX Platform versions master, palm, olive, nutmeg, maple, lilac, koa, or juniper
Description:
The issue is related to inadequate access control in the Open edX Platform, specifically with the AWS S3 Bucket Handler component. This may allow a remote attacker to disclose protected information. Instructors can upload csv files containing learner information to create cohorts in the instructor dashboard, and with certain storage backends, these uploads may become publicly available. The patch ensures that cohorts data uploaded to AWS S3 buckets is written with a private ACL.
Recommendations:
For versions master, palm, olive, nutmeg, maple, lilac, koa, or juniper, apply the patch in commit cb729a3ced0404736dfa0ae768526c82b608657b to ensure that cohorts data uploaded to AWS S3 buckets is written with a private ACL.
Beyond patching, ensure that existing cohorts uploads have a private ACL, or take other precautions to avoid public access.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aws S3