Autolab, a course management service that enables auto-graded programming assignments, has misconfigured reset password permissions in version 3.0.0. For email-based accounts, users with insufficient privileges could reset and theoretically access privileged users' accounts by resetting their passwords. This issue is fixed in version 3.0.1. No known workarounds exist.
References
Configurations
History
14 Nov 2024, 22:49
Type | Values Removed | Values Added |
---|---|---|
First Time |
Autolabproject
Autolabproject autolab |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
CWE | CWE-863 | |
CPE | cpe:2.3:a:autolabproject:autolab:3.0.0:*:*:*:*:*:*:* | |
References | () https://github.com/autolab/Autolab/security/advisories/GHSA-v46j-h43h-rwrm - Vendor Advisory | |
References | () https://github.com/autolab/Autolab/commit/301689ab5c5e39d13bab47b71eaf8998d04bcc9b - Patch |
25 Oct 2024, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-25 13:15
Updated : 2024-11-14 22:49
NVD link : CVE-2024-49376
Mitre link : CVE-2024-49376
JSON object : View
Products Affected
autolabproject
- autolab
CWE
CWE-863
Incorrect Authorization