VYPR
Unrated severityNVD Advisory· Published Nov 18, 2024· Updated Nov 21, 2024

Autolab has vulnerable submission endpoints

CVE-2024-52584

Description

Autolab is a course management service that enables auto-graded programming assignments. There is a vulnerability in version 3.0.1 where CAs can view or edit the grade for any submission ID, even if they are not a CA for the class that has the submission. The endpoints only check that the CAs have the authorization level of a CA in the class in the endpoint, which is not necessarily the class the submission is attached to. Version 3.0.2 contains a patch. No known workarounds are available.

Affected products

2
  • Autolab/Autolabllm-fuzzy2 versions
    = 3.0.1+ 1 more
    • (no CPE)range: = 3.0.1
    • (no CPE)range: = 3.0.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.