Skip to content

fix: apply upstream security patch to remove activation_key exposure from account API#1365

Closed
Gi-ron wants to merge 19 commits intooverhangio:releasefrom
eduNEXT:sgb/openedx-activation-key-exposure
Closed

fix: apply upstream security patch to remove activation_key exposure from account API#1365
Gi-ron wants to merge 19 commits intooverhangio:releasefrom
eduNEXT:sgb/openedx-activation-key-exposure

Conversation

@Gi-ron
Copy link
Copy Markdown
Contributor

@Gi-ron Gi-ron commented Apr 9, 2026

Description

This PR applies an upstream security fix from Open edX by backporting the following commit into the Tutor Open edX Docker image, which removes the activation_key field from the /api/user/v1/accounts/{username} response to prevent a vulnerability where attackers could bypass email verification by combining OAuth2 password grant access for inactive users with direct account activation:

openedx/openedx-platform@21cead2

@Gi-ron Gi-ron force-pushed the sgb/openedx-activation-key-exposure branch from e78470f to 5f2d033 Compare April 9, 2026 20:53
@Gi-ron Gi-ron closed this Apr 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Pending Triage

Development

Successfully merging this pull request may close these issues.

5 participants