CVE-2024-53258
MEDIUMAutolab 3.0.0-3.0.2 - Unauthorized Submission Download via download_all_submissions Feature
Title source: llmDescription
Autolab is a course management service that enables auto-graded programming assignments. From Autolab versions v.3.0.0 onward students can download all assignments from another student, as long as they are logged in, using the download_all_submissions feature. This can allow for leakage of submissions to unauthorized users, such as downloading submissions from other students in the class, or even instructor test submissions, given they know their user IDs. This issue has been patched in commit `1aa4c769` which is not yet in a release version, but is expected to be included in version 3.0.3. Users are advised to either manually patch or to wait for version 3.0.3. As a workaround administrators can disable the feature.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://github.com/autolab/Autolab/security/advisories/GHSA-84qc-7773-2gg3
Scores
CVSS v3
5.3
EPSS
0.0046
EPSS Percentile
36.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-359
CWE-862
Status
published
Products (1)
autolabproject/autolab
3.0.0 - 3.0.2
Published
Nov 25, 2024
Tracked Since
Feb 18, 2026