Open edX Installation Process Exposes MongoDB Instance with Default Credentials

Open edX Installation Process Exposes MongoDB Instance with Default Credentials

CVE-2017-18381 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials.

Learn more about our Cis Benchmark Audit For Mongodb.