Vulnerabilities > CVE-2021-36539 - Authorization Bypass Through User-Controlled Key vulnerability in Instructure Canvas Learning Management Service 20200729

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
instructure
CWE-639

Summary

Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewer based file preview URL (canvadoc_session_url).

Vulnerable Configurations

Part Description Count
Application
Instructure
1