CVE-2024-43782
This validation included protection against malformed translations and translations-based script injections.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.54%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
This openedx-translations repository contains translation files from Open edX repositories to be kept in sync with Transifex. Before moving to pulling translations from the openedx-translations repository via openedx-atlas, translations in the edx-platform repository were validated using edx-i18n-tools. This validation included protection against malformed translations and translations-based script injections. Prior to this patch, the validation implemented in the openedx-translations repository did not include the same protections. The maintainer inspected the translations in the edx-platform directory of both the main and open-release/redwood.master branches of the openedx-translations repository and found no evidence of exploited translation strings.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.54% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- openedx/openedx
- Source
- security-advisories@github.com
References
- https://github.com/openedx/openedx-translations/commit/3c4093705dec99590577c4d8270ce263f7fffc5aPatch
- https://github.com/openedx/openedx-translations/commit/b2444340e8702c7955310331c1db5fd85b25b92bPatch
- https://github.com/openedx/openedx-translations/security/advisories/GHSA-fg8c-2pvj-wx3jPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.