Validation of Translations in Open edX Repositories
CVE-2024-43782
9.8CRITICAL
What is CVE-2024-43782?
The vulnerability in the Open edX translations repository allows for potential security risks associated with malformed translations and script injections. Before implementing necessary updates, translation validation within the edx-platform repository ensured protection against these issues through edx-i18n-tools. However, the openedx-translations repository lacked similar protections, leaving it susceptible to threats. After recent inspections, no evidence of exploited translation strings was discovered, yet proactive steps are critical to enhance the security posture of translation handling across both the main and open-release/redwood.master branches.
Affected Version(s)
openedx-translations < b2444340e8702c7955310331c1db5fd85b25b92b