Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewer based file preview URL (canvadocsessionurl).
{
"severity": "Medium",
"cpes": [
"cpe:2.3:a:instructure:canvas_learning_management_service:*:*:*:*:*:*:*:*"
]
}