CVE-2015-2186: Input Validation

Published Feb 3, 2018
·
Updated

The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use of the string literal "False" instead of a boolean False for the CORSORIGINALLOWALL setting. Note: this vulnerability was fixed on 2015-03-06, but the version number was not changed.

Affected Software

2 affected components
edx Configuration<=1.0
edx edx-platform<=1.6.0

Event History

Feb 3, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2015-2186?

CVE-2015-2186 is considered a moderate severity vulnerability.

2

How do I fix CVE-2015-2186?

To fix CVE-2015-2186, ensure that the CORS_ORIGIN_ALLOW_ALL setting uses a boolean value instead of the string literal 'False'.

3

Which software versions are affected by CVE-2015-2186?

CVE-2015-2186 affects versions of edX Configuration up to 1.0 and edX Open edX Platform up to 1.6.0.

4

Is CVE-2015-2186 still a concern in the latest versions of edX software?

No, CVE-2015-2186 was fixed on March 6, 2015, in the subsequent releases of the software.

5

What type of attack does CVE-2015-2186 enable?

CVE-2015-2186 allows remote websites to spoof edX accounts by exploiting improper handling of the CORS_ORIGIN_ALLOW_ALL setting.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203