CVE-2015-6671: Infoleak
Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging access to a database backup.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6671?
CVE-2015-6671 is considered a critical vulnerability due to the potential unauthorized access to sensitive data.
How do I fix CVE-2015-6671?
To fix CVE-2015-6671, upgrade your edX platform to version 2015-08-25 or later.
Who is affected by CVE-2015-6671?
Users of Open edX edx-platform versions prior to 2015-08-25 are affected by CVE-2015-6671.
What does CVE-2015-6671 exploit?
CVE-2015-6671 exploits the storage of SAML SSO secrets in the database, making them vulnerable to attackers with database access.
What are the potential impacts of CVE-2015-6671?
The potential impacts of CVE-2015-6671 include data leakage and unauthorized access to sensitive information stored in the SAML SSO secrets.