CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
23h00 +00:00 |
Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewer based file preview URL (canvadoc_session_url). | 6.5 |
Medium |
|
15h36 +00:00 |
Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET requests to arbitrary domains. | 5.8 |
Medium |