The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials.
References
Link | Resource |
---|---|
https://groups.google.com/forum/#!topic/openedx-announce/mpyyx34LWSY | Third Party Advisory |
https://groups.google.com/forum/#!topic/openedx-announce/jRXyo1HJzNk | Mitigation Third Party Advisory |
Information
Published : 2019-07-30 12:15
Updated : 2020-01-07 10:19
NVD link : CVE-2017-18381
Mitre link : CVE-2017-18381
JSON object : View
CWE
CWE-254
7PK - Security Features
Products Affected
mongodb
- mongodb
edx
- edx-platform