Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-45955 | Autolab is a course management service that enables auto-graded programming assignments. There is a vulnerability in version 3.0.1 where CAs can view or edit the grade for any submission ID, even if they are not a CA for the class that has the submission. The endpoints only check that the CAs have the authorization level of a CA in the class in the endpoint, which is not necessarily the class the submission is attached to. Version 3.0.2 contains a patch. No known workarounds are available. |
Tue, 21 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Autolabproject
Autolabproject autolab |
|
| CPEs | cpe:2.3:a:autolabproject:autolab:3.0.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Autolabproject
Autolabproject autolab |
|
| Metrics |
cvssV3_1
|
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 19 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 18 Nov 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Autolab is a course management service that enables auto-graded programming assignments. There is a vulnerability in version 3.0.1 where CAs can view or edit the grade for any submission ID, even if they are not a CA for the class that has the submission. The endpoints only check that the CAs have the authorization level of a CA in the class in the endpoint, which is not necessarily the class the submission is attached to. Version 3.0.2 contains a patch. No known workarounds are available. | |
| Title | Autolab has vulnerable submission endpoints | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-11-21T14:54:45.418Z
Reserved: 2024-11-14T15:05:46.766Z
Link: CVE-2024-52584
Updated: 2024-11-19T15:33:08.397Z
Status : Analyzed
Published: 2024-11-18T21:15:07.047
Modified: 2025-01-21T17:55:15.340
Link: CVE-2024-52584
No data.
OpenCVE Enrichment
No data.
EUVD