Autolab, a course management service that enables auto-graded programming assignments, has misconfigured reset password permissions in version 3.0.0. For email-based accounts, users with insufficient privileges could reset and theoretically access privileged users' accounts by resetting their passwords. This issue is fixed in version 3.0.1. No known workarounds exist.
History

Thu, 14 Nov 2024 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Autolabproject
Autolabproject autolab
Weaknesses CWE-863
CPEs cpe:2.3:a:autolabproject:autolab:3.0.0:*:*:*:*:*:*:*
Vendors & Products Autolabproject
Autolabproject autolab
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Fri, 25 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 25 Oct 2024 13:15:00 +0000

Type Values Removed Values Added
Description Autolab, a course management service that enables auto-graded programming assignments, has misconfigured reset password permissions in version 3.0.0. For email-based accounts, users with insufficient privileges could reset and theoretically access privileged users' accounts by resetting their passwords. This issue is fixed in version 3.0.1. No known workarounds exist.
Title Autolab Has Misconfigured Reset Password Permissions
Weaknesses CWE-287
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-10-25T12:50:33.130Z

Updated: 2024-10-25T15:05:44.274Z

Reserved: 2024-10-14T13:56:34.812Z

Link: CVE-2024-49376

cve-icon Vulnrichment

Updated: 2024-10-25T15:05:39.337Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-25T13:15:17.957

Modified: 2024-11-14T22:49:50.667

Link: CVE-2024-49376

cve-icon Redhat

No data.