Skip to content

Vulnerable submission endpoints

High
dwang3851 published GHSA-rjg4-cf66-x6gr Nov 18, 2024

Package

bundler Autolab (RubyGems)

Affected versions

3.0.1

Patched versions

3.0.2

Description

Impact

There is a vulnerability where CAs can view or edit the grade for any submission ID, even if they are not a CA for the class that has the submission. The endpoints only check that the CAs have the authorization level of a CA in the class in the endpoint, which is not necessarily the class the submission is attached to.

Patches

Will be patched soon

Workarounds

No workarounds

Severity

High

CVE ID

CVE-2024-52584

Weaknesses

No CWEs

Credits