tutor
The Docker-based Open edX distribution designed for peace of mind
Activity
- Latest release
- 5h ago
- Total releases
- 123
- Cadence
- ~17 days
- Last 12 months
- 18
Reach
- Stars
- 1.1k
Details
- License
- unknown
- First release
- Feb 29, 2012
| Version | Released | |
|---|---|---|
23.0.0.dev3180
pre
| ||
22.0.2
patch
| ||
22.0.1
patch
| ||
22.0.0
major
| ||
21.0.9
patch
| ||
21.0.8
patch
| ||
21.0.7
patch
| ||
21.0.6
patch
| ||
21.0.5
patch
| ||
21.0.4
patch
| ||
21.0.3
patch
| ||
21.0.2
patch
| ||
21.0.1
patch
| ||
21.0.0
major
| ||
20.0.5
patch
| ||
20.0.4
patch
| ||
20.0.3
patch
| ||
20.0.2
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
20.0.1
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
20.0.0
major
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
19.0.5
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
19.0.4
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
19.0.3
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
19.0.2
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
19.0.1
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
19.0.0
major
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
18.2.2
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
18.2.1
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
18.2.0
minor
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
18.1.4
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
18.1.3
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
18.1.2
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
18.1.1
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
18.1.0
minor
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
18.0.0
major
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
17.0.6
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
17.0.5
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
17.0.4
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
17.0.3
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
17.0.2
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
17.0.1
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
17.0.0
major
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
16.1.8
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
16.1.7
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
16.1.6
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
16.1.5
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
16.1.4
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
13.3.2
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
14.2.5
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev | ||
15.3.9
patch
1 CVE
CVE-2025-65681
GHSA-gq25-78jf-v78c
PYSEC-2025-219
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. Affected versions
0.1
0.2
0.2.1
12.0.1
12.0.2
12.0.3
12.0.4
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
+ 94 more Show less
12.1.5
12.1.6
12.1.7
12.2.0
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.10
13.1.11
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
13.1.7
13.1.8
13.1.9
13.2.0
13.2.1
13.2.2
13.2.3
13.3.0
13.3.1
13.3.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.1.0
14.1.1
14.1.2
14.2.0
14.2.1
14.2.2
14.2.3
14.2.4
14.2.5
15.0.0
15.1.0
15.2.0
15.3.0
15.3.1
15.3.2
15.3.3
15.3.4
15.3.5
15.3.6
15.3.7
15.3.8
15.3.9
16.0.0
16.0.1
16.0.2
16.0.3
16.0.5
16.1.0
16.1.1
16.1.2
16.1.3
16.1.4
16.1.5
16.1.6
16.1.7
16.1.8
17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
18.0.0
18.1.0
18.1.1
18.1.2
18.1.3
18.1.4
18.2.0
18.2.1
18.2.2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4
19.0.5
20.0.0
20.0.1
20.0.2
References Updated Jun 08, 2026 · Source: OSV.dev |