CVE-2024-49376

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-49376
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-49376.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-49376
Aliases
Published
2024-10-25T13:15:17Z
Modified
2024-11-15T01:46:35.678618Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Autolab, a course management service that enables auto-graded programming assignments, has misconfigured reset password permissions in version 3.0.0. For email-based accounts, users with insufficient privileges could reset and theoretically access privileged users' accounts by resetting their passwords. This issue is fixed in version 3.0.1. No known workarounds exist.

References

Affected packages

Git / github.com/autolab/autolab

Affected ranges

Type
GIT
Repo
https://github.com/autolab/autolab
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

2.*

2.0.4
2.0.8
2.1.0
2.2.0
2.2.1

v1.*

v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.1.0
v1.1.1
v1.2.0
v1.3.0
v1.4.0
v1.4.1
v1.5.0
v1.5.1
v1.6.0
v1.7.0

v2.*

v2.0.2
v2.0.3
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.10.0
v2.11.0
v2.11.1
v2.12.0
v2.13.0
v2.2.0
v2.2.1
v2.3.0
v2.4.0
v2.6.0
v2.7.0
v2.8.0
v2.9.0

v3.*

v3.0.0