CVE-2024-53258

Autolab is a course management service that enables auto-graded programming assignments. From Autolab versions v.3.0.0 onward students can download all assignments from another student, as long as they are logged in, using the download_all_submissions feature. This can allow for leakage of submissions to unauthorized users, such as downloading submissions from other students in the class, or even instructor test submissions, given they know their user IDs. This issue has been patched in commit `1aa4c769` which is not yet in a release version, but is expected to be included in version 3.0.3. Users are advised to either manually patch or to wait for version 3.0.3. As a workaround administrators can disable the feature.
Configurations

Configuration 1 (hide)

cpe:2.3:a:autolabproject:autolab:*:*:*:*:*:*:*:*

History

07 Apr 2025, 19:56

Type Values Removed Values Added
CPE cpe:2.3:a:autolabproject:autolab:*:*:*:*:*:*:*:*
References () https://github.com/autolab/Autolab/commit/1aa4c7690892fb458d2c61ff86739f368e34769d - () https://github.com/autolab/Autolab/commit/1aa4c7690892fb458d2c61ff86739f368e34769d - Patch
References () https://github.com/autolab/Autolab/security/advisories/GHSA-84qc-7773-2gg3 - () https://github.com/autolab/Autolab/security/advisories/GHSA-84qc-7773-2gg3 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
First Time Autolabproject
Autolabproject autolab

Information

Published : 2024-11-25 20:15

Updated : 2025-04-07 19:56


NVD link : CVE-2024-53258

Mitre link : CVE-2024-53258

CVE.ORG link : CVE-2024-53258


JSON object : View

Products Affected

autolabproject

  • autolab
CWE
CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

CWE-862

Missing Authorization