SECURITY UPDATE |  |
Summary:
A security audit has identified that Canvas LMS is vulnerable to a cross-site request forgery attack via unprotected JSON responses to various AJAX request calls. This attack could allow a malicious third-party site to steal private information, if a user were to visit that malicious site while logged in to Canvas.
This attack is not possible in the newest releases of major web browsers, but still affects some officially supported browser versions such as previous Safari and Chrome releases.
Status:
This vulnerability was fixed in the 2011-12-10 release, by prepending a protective javascript loop to GET request JSON responses.