Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users created with type roleview can log in as a normal user. This can result in illegal access being granted to the system. Version 23.3 fixes this vulnerability.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00049}

epss

{'score': 0.0005}


Fri, 22 Nov 2024 12:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 0.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N'}


Tue, 15 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Sakaiproject
Sakaiproject sakai
CPEs cpe:2.3:a:sakaiproject:sakai:*:*:*:*:*:*:*:*
Vendors & Products Sakaiproject
Sakaiproject sakai
Metrics cvssV3_1

{'score': 0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Oct 2024 16:00:00 +0000

Type Values Removed Values Added
Description Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users created with type roleview can log in as a normal user. This can result in illegal access being granted to the system. Version 23.3 fixes this vulnerability.
Title Sakai: Kernel users created with type roleview can login as a normal user
Weaknesses CWE-285
CWE-863
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-11-21T16:53:20.053Z

Reserved: 2024-10-04T16:00:09.630Z

Link: CVE-2024-47876

cve-icon Vulnrichment

Updated: 2024-10-15T16:17:58.796Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-15T16:15:05.420

Modified: 2024-11-21T17:15:18.227

Link: CVE-2024-47876

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.