vendor:
OpenEDX Platform
by:
Daniel Monzón (stark0de)
8.8
CVSS
HIGH
Remote Code Execution
CWE
Product Name: OpenEDX Platform
Affected Version From: Ironwood 2.5
Affected Version To: Ironwood 2.5
Patch Exists: NO
Related CWE: CVE-2020-13144
CPE:
Platforms Tested: Debian x64
2020
OpenEDX platform Ironwood 2.5 – Remote Code Execution
OpenEDX Platform Ironwood version 2.5 suffers from a RCE vulnerability when the use of CodeJail is not enforced. This is an authenticated vulnerability, so you need to register an account, go to /edx-studio and create a new course, section, subsection, unit, and add a new component with a custom Python evaluated code. By introducing a payload in the problem section, an attacker can execute arbitrary commands on the target machine.
Mitigation:
Enforce the use of CodeJail in the OpenEDX platform Ironwood version 2.5 to prevent the execution of arbitrary commands.