CVE-2017-18381: High severity edx open edx platform vulnerability
Published Jul 30, 2019
·Updated
The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials.
Affected Software
1 affected component
edx edx-platform<2017-01-10
Event History
Jul 30, 2019
CVE Published
via MITRE·06:38 PM
Data Sourced
via MITRE·06:38 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2017-18381.
2
What is the severity of CVE-2017-18381?
The severity of CVE-2017-18381 is high with a severity value of 7.2.
3
What does CVE-2017-18381 affect?
CVE-2017-18381 affects the Open edX platform prior to 2017-01-10.
4
How does CVE-2017-18381 expose a MongoDB instance?
CVE-2017-18381 exposes a MongoDB instance to external connections during the installation process of Open edX.
5
Are there any available references for CVE-2017-18381?
Yes, you can find more information about CVE-2017-18381 in the following references: [1](https://groups.google.com/forum/#!topic/openedx-announce/jRXyo1HJzNk), [2](https://groups.google.com/forum/#!topic/openedx-announce/mpyyx34LWSY).