Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewer based file preview URL (canvadocsessionurl).
{ "cpes": [ "cpe:2.3:a:instructure:canvas_learning_management_service:*:*:*:*:*:*:*:*" ], "severity": "Medium" }