CVE-2024-53258

MEDIUM

Autolab < 3.0.2 - Missing Authorization

Title source: rule
STIX 2.1

Description

Autolab is a course management service that enables auto-graded programming assignments. From Autolab versions v.3.0.0 onward students can download all assignments from another student, as long as they are logged in, using the download_all_submissions feature. This can allow for leakage of submissions to unauthorized users, such as downloading submissions from other students in the class, or even instructor test submissions, given they know their user IDs. This issue has been patched in commit `1aa4c769` which is not yet in a release version, but is expected to be included in version 3.0.3. Users are advised to either manually patch or to wait for version 3.0.3. As a workaround administrators can disable the feature.

Scores

CVSS v3 5.3
EPSS 0.0038
EPSS Percentile 59.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-359 CWE-862
Status published
Products (1)
autolabproject/autolab 3.0.0 - 3.0.2
Published Nov 25, 2024
Tracked Since Feb 18, 2026