Validation of Translations in Open edX Repositories
CVE-2024-43782
Key Information:
- Vendor
- Openedx
- Status
- Openedx-translations
- Vendor
- CVE Published:
- 23 August 2024
Summary
The vulnerability in the Open edX translations repository allows for potential security risks associated with malformed translations and script injections. Before implementing necessary updates, translation validation within the edx-platform repository ensured protection against these issues through edx-i18n-tools. However, the openedx-translations repository lacked similar protections, leaving it susceptible to threats. After recent inspections, no evidence of exploited translation strings was discovered, yet proactive steps are critical to enhance the security posture of translation handling across both the main and open-release/redwood.master branches.
Affected Version(s)
openedx-translations < b2444340e8702c7955310331c1db5fd85b25b92b
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved