Canvas version 2020-07-29 is susceptible to blind server-side request forgery. An attacker can cause Canvas to perform HTTP GET requests to arbitrary domains and thus potentially access sensitive information, modify data, and/or execute unauthorized operations.
id: CVE-2020-5775
info:
name: Canvas LMS v2020-07-29 - Blind Server-Side Request Forgery
author
...