CVE-2024-47876
HIGHSakai 23.0-23.1 - Improper Authorization via Roleview User Type
Title source: llmDescription
Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users created with type roleview can log in as a normal user. This can result in illegal access being granted to the system. Version 23.3 fixes this vulnerability.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
https://github.com/sakaiproject/sakai/security/advisories/GHSA-cx95-q6gx-w4qp
Patch x_refsource_misc
https://github.com/sakaiproject/sakai/commit/a9aadd9347cfb204515e89ac0163e1be9e56cc41
Permissions Required x_refsource_misc
https://sakaiproject.atlassian.net/browse/SAK-50571
Scores
CVSS v3
8.8
EPSS
0.0055
EPSS Percentile
41.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-285
CWE-863
Status
published
Products (2)
org.sakaiproject.kernel/sakai-kernel-impl
23.0 - 23.3Maven
sakailms/sakai
23.0 - 23.2
Published
Oct 15, 2024
Tracked Since
Feb 18, 2026