PT-2024-22322 · Judge0 · Judge0

Stacksparrow4

·

Published

2024-04-18

·

Updated

2024-05-02

·

CVE-2024-28189

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Judge0 versions prior to 1.13.1
Description The issue arises from the application's use of the UNIX chown command on an untrusted file within the sandbox. An attacker can exploit this by creating a symbolic link (symlink) to a file outside the sandbox, allowing the attacker to run chown on arbitrary files outside of the sandbox. This can be used to bypass a previous patch and obtain a complete sandbox escape.
Recommendations For versions prior to 1.13.1, update to version 1.13.1 to resolve the issue. As a temporary workaround, consider restricting the use of the chown command within the sandbox until the update is applied.

Exploit

Fix

Link Following

Weakness Enumeration

Related Identifiers

CVE-2024-28189
GHSA-3XPW-36V7-2CMG
GHSA-H9G2-45C8-89CF

Affected Products

Judge0