Hello all:
I want to let you know that we've just released a security patch for 
edx-ecommerce service. The patch removes the public access to the ecommerce 
catalogue directory and it’s content. A user before the fix can take advantage 
of the visibility and use any edx course coupons to checkout enrollment seats.

Please see the fix here 
https://github.com/edx/ecommerce/commit/5ddce0941bc9521bd52b0bd68d531daf04500942
 
<https://github.com/edx/ecommerce/commit/5ddce0941bc9521bd52b0bd68d531daf04500942>

Thanks, and please let me know if you have any questions!


Best

Simon Chen
sc...@edx.org



-- 
You received this message because you are subscribed to the Google Groups 
"General Open edX discussion" group.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/edx-code/9C416994-3A8D-4CE0-85FD-24C09164940D%40edx.org.

Reply via email to