PT-2024-22675 · Judge0 · Judge0
Stacksparrow4
·
Published
2024-04-18
·
Updated
2024-05-02
·
CVE-2024-29021
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Judge0 versions prior to 1.13.1
Description
The default configuration of Judge0 leaves the service vulnerable to a sandbox escape via Server Side Request Forgery (SSRF). This allows an attacker with sufficient access to the Judge0 API to obtain unsandboxed code execution as root on the target machine.
Recommendations
For versions prior to 1.13.1, update to version 1.13.1 to resolve the issue. As a temporary workaround, consider restricting access to the Judge0 API to minimize the risk of exploitation.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Judge0