Back to Database
Status published
Medium
CVE-2024-22209
XBlock custom auth does not respect JWT Scopes
Vulnerability Description
Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call endpoints exceeding their access. This vulnerability has been patched in commit 019888f.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-22209
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/openedx/edx-platform/security/advisories/GHSA-qx8m-mqx3-j9fm
- https://github.com/openedx/edx-platform/commit/019888f3d15beaebcb7782934f6c43b0c2b3735e
- https://github.com/openedx/edx-platform/blob/0b3e4d73b6fb6f41ae87cf2b77bca12052ee1ac8/lms/djangoapps/courseware/block_render.py#L752-L775
More from openedx
View All →CVE-2025-68270
CourseLimitedStaff Role Allows Studio Access
Critical
9.9
CVE-2025-47942
Learners on edX Platform can download python_lib.zip
Medium
5.3
CVE-2024-43782
openedx-translations's Atlas translations for Open edX missing validation
High
7.7
CVE-2024-41806
Open edX Platform's instructor upload CSV for cohort creation not Private by Default
Medium
5.3
CVE-2023-23611
xblock-lti-consumer contain Missing Authorization in Grade Pass Back Implementation
Medium
5.4
Affected Vendor
openedx
View all reports →Affected Software
edx-platform
Vulnerable Versions:
< commit 019888f
Timeline
Official Publish:
January 13th, 2024
Last Modified:
October 24th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N