PT-2024-35697 · Autolab · Autolab
20Wildmanj
·
Published
2024-11-25
·
Updated
2024-11-25
·
CVE-2024-53258
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Autolab versions 3.0.0 through 3.0.2
Description
Autolab is a course management service that enables auto-graded programming assignments. The issue allows students to download all assignments from another student, as long as they are logged in, using the
download all submissions feature. This can lead to leakage of submissions to unauthorized users, such as downloading submissions from other students in the class, or even instructor test submissions, given they know their user IDs.Recommendations
For Autolab versions 3.0.0 through 3.0.2, users are advised to either manually patch with commit
1aa4c769 or wait for version 3.0.3.
As a temporary workaround, administrators can disable the download all submissions feature to minimize the risk of exploitation.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Autolab