CVE-2024-53258 is a medium-severity vulnerability affecting Autolab versions 3.0.0 and later, a course management service. It allows logged-in students to download all submissions from other students or even instructor test submissions by knowing their user IDs, leading to unauthorized information leakage. The vulnerability has a CVSS score of 5.3 (MEDIUM) due to its network-based attack vector, high attack complexity, and high confidentiality impact. While a patch exists in commit 1aa4c769 and is expected in version 3.0.3, there is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, <= 3.0.2CPE matchmatch criteria | cpe:2.3:a:autolabproject:autolab:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.