Description
PutongOJ is online judging software. Prior to version 2.1.0-beta.1, unprivileged users can escalate privileges by constructing requests. This can lead to unauthorized access, enabling users to perform admin-level operations, potentially compromising sensitive data and system integrity. This problem has been fixed in v2.1.0.beta.1. As a workaround, one may apply the patch from commit `211dfe9` manually.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
https://github.com/acm309/PutongOJ/security/advisories/GHSA-gj6h-73c5-xw6f
Patch x_refsource_misc
https://github.com/acm309/PutongOJ/commit/211dfe9ebf1c6618ce5396b0338de4f9b580715e#diff-782628b47d666d5d551e040815ca3f80c0704397258718f0e0f31164608ea7beL118-R120
Release Notes x_refsource_misc
https://github.com/acm309/PutongOJ/releases/tag/v2.1.0-beta.1
Scores
CVSS v3
9.1
EPSS
0.0045
EPSS Percentile
35.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-306
Status
published
Products (1)
acm309/PutongOJ
< 2.1.0-beta.1
Published
Oct 17, 2024
Tracked Since
Feb 18, 2026