Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-39865 | Lack of access control in ChallengeSolves (/api/v1/challenges/<challenge id>/solves) of CTFd v2.0.0 - v3.7.2 allows authenticated users to retrieve a list of users who have solved the challenge, regardless of the Account Visibility settings. The issue is fixed in v3.7.3+. |
Mon, 10 Feb 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Wed, 09 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 09 Oct 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lack of access control in ChallengeSolves (/api/v1/challenges/<challenge id>/solves) of CTFd v2.0.0 - v3.7.2 allows authenticated users to retrieve a list of users who have solved the challenge, regardless of the Account Visibility settings. The issue is fixed in v3.7.3+. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-10T22:49:11.301Z
Reserved: 2024-08-05T00:00:00.000Z
Link: CVE-2024-42988
Updated: 2024-10-09T18:13:47.163Z
Status : Deferred
Published: 2024-10-09T17:15:16.337
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-42988
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:14:55Z
EUVD