CVE-2024-52584 - CVE House
Back to Database
Status published Medium CVE-2024-52584

Autolab has vulnerable submission endpoints

Vulnerability Description

Autolab is a course management service that enables auto-graded programming assignments. There is a vulnerability in version 3.0.1 where CAs can view or edit the grade for any submission ID, even if they are not a CA for the class that has the submission. The endpoints only check that the CAs have the authorization level of a CA in the class in the endpoint, which is not necessarily the class the submission is attached to. Version 3.0.2 contains a patch. No known workarounds are available.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-52584

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Autolab
Vulnerable Versions:
= 3.0.1

Timeline

Official Publish: November 18th, 2024
Last Modified: November 21st, 2024
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)