Autolab, a course management service that enables auto-graded programming assignments, has misconfigured reset password permissions in version 3.0.0. For email-based accounts, users with insufficient privileges could reset and theoretically access privileged users' accounts by resetting their passwords. This issue is fixed in version 3.0.1. No known workarounds exist.
References
Configurations
History
No history.
Information
Published : 2024-10-25 13:15
Updated : 2024-11-14 22:49
NVD link : CVE-2024-49376
Mitre link : CVE-2024-49376
CVE.ORG link : CVE-2024-49376
JSON object : View
Products Affected
autolabproject
- autolab