File Download Vulnerability in Open edX Learning Management Platform
CVE-2025-47942

5.3MEDIUM

Key Information:

Vendor

Openedx

Vendor
CVE Published:
21 May 2025

What is CVE-2025-47942?

The Open edX Platform, a popular learning management system, has a vulnerability where the python_lib.zip asset can be downloaded without restriction prior to a specific commit. This poses a risk as the asset often contains custom grading code or sensitive information related to course assessments. While the openedx/configuration repository provided a temporary nginx rule to mitigate this exposure, it has been deprecated, leaving many deployments open to risk. The patch introduced in commit 6740e75c0fdc7ba095baf88e9f5e4f3e15cfd8ba restricts access to this asset, limiting downloads to course team members and site staff, thereby enhancing the security of the platform.

Affected Version(s)

edx-platform < 6740e75c0fdc7ba095baf88e9f5e4f3e15cfd8ba

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.