CVE-2024-22209: Edx Edx-Platform

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call endpoints exceeding their access. This vulnerability has been patched in commit 019888f.

Affected products

  • Edx Edx-Platform: before 2024-01-12 (fixed in 2024-01-12)

Published 2024-01-13. Last modified 2026-06-17.