CVE-2023-44395
Last modified
CVE-2023-44395 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Autolab is a course management service that enables instructors to offer autograded programming assignments to their students over the Web. Path traversal vulnerabilities were discovered in Autolab's assessment functionality in versions of Autolab prior to 2.12.0, whereby instructors can perform arbitrary file reads. EPSS estimates a 0.60% chance of exploitation in the next 30 days.
Description
Autolab is a course management service that enables instructors to offer autograded programming assignments to their students over the Web. Path traversal vulnerabilities were discovered in Autolab's assessment functionality in versions of Autolab prior to 2.12.0, whereby instructors can perform arbitrary file reads. Version 2.12.0 contains a patch. There are no feasible workarounds for this issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Autolabproject | Autolab | < 2.12.0 |
References
- https://www.stackhawk.com/blog/rails-path-traversal-guide-examples-and-prevention/Technical Description
- https://www.stackhawk.com/blog/rails-path-traversal-guide-examples-and-prevention/Technical Description
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-44395?
How severe is CVE-2023-44395?
How do I fix CVE-2023-44395?
Are you affected by CVE-2023-44395?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
