CVE-2024-48920
CVSS V2 None
CVSS V3 None
Description
PutongOJ is online judging software. Prior to version 2.1.0-beta.1, unprivileged users can escalate privileges by constructing requests. This can lead to unauthorized access, enabling users to perform admin-level operations, potentially compromising sensitive data and system integrity. This problem has been fixed in v2.1.0.beta.1. As a workaround, one may apply the patch from commit `211dfe9` manually.
Overview
- CVE ID
- CVE-2024-48920
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-10-17T14:24:08.417Z
- Last Modified Date
- 2024-10-17T16:11:05.089Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/acm309/PutongOJ/security/advisories/GHSA-gj6h-73c5-xw6f | x_refsource_CONFIRM |
https://github.com/acm309/PutongOJ/commit/211dfe9ebf1c6618ce5396b0338de4f9b580715e#diff-782628b47d666d5d551e040815ca3f80c0704397258718f0e0f31164608ea7beL118-R120 | x_refsource_MISC |
https://github.com/acm309/PutongOJ/releases/tag/v2.1.0-beta.1 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-48920 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-48920 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-10-18 13:10:44 | Added to TrackCVE |