Known Vulnerabilities for Canvas Learning Management Service by Instructure
Listed below are 2 of the newest known vulnerabilities associated with "Canvas Learning Management Service" by "Instructure".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-36539 json | Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewe... | 6.5 - MEDIUM | 2023-01-26 | 2024-01-25 |
| CVE-2020-5775 json | Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas applicatio... | 5.8 - MEDIUM | 2020-08-21 | 2020-08-26 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Instructure | Canvas Learning Management Service | 2020-07-29 |