XBlock custom auth does not respect JWT Scopes
CVE-2024-22209
6.4MEDIUM
What is CVE-2024-22209?
Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call endpoints exceeding their access. This vulnerability has been patched in commit 019888f.
Affected Version(s)
edx-platform < commit 019888f