CVE-2024-28189 is a critical vulnerability in Judge0, an open-source online code execution system, affecting versions prior to 1.13.1. It allows an attacker to bypass the sandbox by creating a symbolic link to an arbitrary file, enabling the chown command to be executed outside the sandbox. This vulnerability has a CVSS score of 10.0 (Critical) due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability, potentially leading to a complete sandbox escape. While not directly impactful, it is crucial for bypassing the patch for CVE-2024-28185. Exploit code is publicly available via a Metasploit module, and it has garnered significant community discussion and media coverage, indicating active awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Judge0 | Judge0 | <= 1.13.0CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.