Security Alert: Cross Domain Referer Leakage via Social Follow Us Links

March 12, 2015 | By

Security Alert

Severity: High
Category: Cross Domain Referer Leakage
Affected Projects: edx-platform
Reporter: Smit B. Shah & Nikhil Srivastava from Techdefence Labs
Permanent URL: https://openedx.org/CVE-2015-2286

On January 11, 2015 a security vulnerability was reported by Smit B. Shah and Nikhil Srivastava that caused password reset tokens to be forwarded to third-party social networks in the HTTP referrer header.  The vulnerabilty would allow privileged users at those third-parties to gain access to user generated password reset tokens.  A patch that resolved this bug was comitted on January 29th, 2015.  The resolution of this issue was announced via the security-notifications@edx.org list on January 30, 2015.

The Common Vulnerabilities and Exposures (CVE) project has assigned the name CVE-2015-2286 to this issue. This is an entry on the CVE list (http://cve.mitre.org), which standardizes names for security problems.

More Information

Social sharing links in the footer of edX were present on the target page specified in password reset email.  In the case that a user clicked the emailed link to reset their password and subsequently clicked one of the third-party Follow Us links in the edx footer, the HTTP Referrer header would contain the password reset token.  This token would then be available either in logs or code running at the third-party.

The bug was introduced in this commit.

The bug was fixed in this commit.

Loading

Start the discussion at discuss.openedx.org

Time For More? Check out the articles below.

Open edX platform earns LTI® Advantage Certification
Juniper is here!
edX Sponsorship Demos
Cancelling the 2020 Open edX Conference
Join the Open edX Conference 2026!

The 2026 Open edX Conference will present innovative use cases for one of the world’s best open source online learning management systems, the Open edX platform, and discover the latest advancements in instructional design, course constellation, and methods for operating & extending the Open edX platform, including breakthrough technologies, such as generative AI.