Autolab, a course management service that enables auto-graded programming assignments, has misconfigured reset password permissions in version 3.0.0. For email-based accounts, users with insufficient privileges could reset and theoretically access privileged users' accounts by resetting their passwords. This issue is fixed in version 3.0.1. No known workarounds exist.
References
Configurations
History
14 Nov 2024, 22:49
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
References | () https://github.com/autolab/Autolab/commit/301689ab5c5e39d13bab47b71eaf8998d04bcc9b - Patch | |
References | () https://github.com/autolab/Autolab/security/advisories/GHSA-v46j-h43h-rwrm - Vendor Advisory | |
CPE | cpe:2.3:a:autolabproject:autolab:3.0.0:*:*:*:*:*:*:* | |
First Time |
Autolabproject autolab
Autolabproject |
|
CWE | CWE-863 |
28 Oct 2024, 13:58
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
25 Oct 2024, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-25 13:15
Updated : 2024-11-14 22:49
NVD link : CVE-2024-49376
Mitre link : CVE-2024-49376
CVE.ORG link : CVE-2024-49376
JSON object : View
Products Affected
autolabproject
- autolab