Validation of Translations in Open edX Repositories
CVE-2024-43782

9.8CRITICAL

Key Information:

Vendor
Openedx
Status
Openedx-translations
Vendor
CVE Published:
23 August 2024

Summary

The vulnerability in the Open edX translations repository allows for potential security risks associated with malformed translations and script injections. Before implementing necessary updates, translation validation within the edx-platform repository ensured protection against these issues through edx-i18n-tools. However, the openedx-translations repository lacked similar protections, leaving it susceptible to threats. After recent inspections, no evidence of exploited translation strings was discovered, yet proactive steps are critical to enhance the security posture of translation handling across both the main and open-release/redwood.master branches.

Affected Version(s)

openedx-translations < b2444340e8702c7955310331c1db5fd85b25b92b

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.