CVE-2015-2186
Last modified
CVE-2015-2186 is a vulnerability of currently unknown severity. The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use of the string literal "False" instead of a boolean False for the CORS_ORIGIN_ALLOW_ALL setting. Note: this vulnerability was fixed on 2015-03-06, but the version number was not changed.. EPSS estimates a 1.13% chance of exploitation in the next 30 days.
Description
The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use of the string literal "False" instead of a boolean False for the CORS_ORIGIN_ALLOW_ALL setting. Note: this vulnerability was fixed on 2015-03-06, but the version number was not changed.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Edx | Configuration | <= 1.0 |
| Edx | Edx-Platform | <= 1.6.0 |
References
- https://github.com/edx/configuration/pull/1885/filesPatch, Third Party Advisory
- https://open.edx.org/CVE-2015-2186Vendor Advisory
- https://github.com/edx/configuration/pull/1885/filesPatch, Third Party Advisory
- https://open.edx.org/CVE-2015-2186Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-2186?
How severe is CVE-2015-2186?
How do I fix CVE-2015-2186?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-2179The xaviershay-dm-rails gem 0.10.3.8 for Ruby allows local u…5.5
- CVE-2015-2180The DBMail driver in the Password plugin in Roundcube before…
- CVE-2015-2181Multiple buffer overflows in the DBMail driver in the Passwo…
- CVE-2015-2182Multiple cross-site scripting (XSS) vulnerabilities in ZeusC…
- CVE-2015-2183Multiple SQL injection vulnerabilities in the administrative…
- CVE-2015-2184ZeusCart 4 allows remote attackers to obtain configuration i…
- CVE-2015-2187The dissect_atn_cpdlc_heur function in asn1/atn-cpdlc/packet…
- CVE-2015-2188epan/dissectors/packet-wcp.c in the WCP dissector in Wiresha…
- CVE-2015-2189Off-by-one error in the pcapng_read function in wiretap/pcap…
- CVE-2015-2190epan/proto.c in Wireshark 1.12.x before 1.12.4 does not prop…
- CVE-2015-2191Integer overflow in the dissect_tnef function in epan/dissec…
- CVE-2015-2192Integer overflow in the dissect_osd2_cdb_continuation functi…
Are you affected by CVE-2015-2186?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
