Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewer based file preview URL (canvadocsessionurl).
{ "severity": "Medium", "cpes": [ "cpe:2.3:a:instructure:canvas_learning_management_service:*:*:*:*:*:*:*:*" ] }