Description
PutongOJ is online judging software. Prior to version 2.1.0-beta.1, unprivileged users can escalate privileges by constructing requests. This can lead to unauthorized access, enabling users to perform admin-level operations, potentially compromising sensitive data and system integrity. This problem has been fixed in v2.1.0.beta.1. As a workaround, one may apply the patch from commit `211dfe9` manually.
Published: 2024-10-17
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-43134 PutongOJ is online judging software. Prior to version 2.1.0-beta.1, unprivileged users can escalate privileges by constructing requests. This can lead to unauthorized access, enabling users to perform admin-level operations, potentially compromising sensitive data and system integrity. This problem has been fixed in v2.1.0.beta.1. As a workaround, one may apply the patch from commit `211dfe9` manually.
History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00134}

epss

{'score': 0.00137}


Thu, 17 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Putongoj
Putongoj putongoj
CPEs cpe:2.3:a:putongoj:putongoj:*:*:*:*:*:*:*:*
Vendors & Products Putongoj
Putongoj putongoj
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Oct 2024 14:30:00 +0000

Type Values Removed Values Added
Description PutongOJ is online judging software. Prior to version 2.1.0-beta.1, unprivileged users can escalate privileges by constructing requests. This can lead to unauthorized access, enabling users to perform admin-level operations, potentially compromising sensitive data and system integrity. This problem has been fixed in v2.1.0.beta.1. As a workaround, one may apply the patch from commit `211dfe9` manually.
Title PutongOJ: unprivileged users can escalate privileges by constructing requests
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Putongoj Putongoj
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-10-17T16:11:05.089Z

Reserved: 2024-10-09T22:06:46.172Z

Link: CVE-2024-48920

cve-icon Vulnrichment

Updated: 2024-10-17T16:10:57.691Z

cve-icon NVD

Status : Deferred

Published: 2024-10-17T15:15:13.603

Modified: 2026-04-15T00:35:42.020

Link: CVE-2024-48920

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses