Vulnerability Description
PutongOJ is online judging software. Prior to version 2.1.0-beta.1, unprivileged users can escalate privileges by constructing requests. This can lead to unauthorized access, enabling users to perform admin-level operations, potentially compromising sensitive data and system integrity. This problem has been fixed in v2.1.0.beta.1. As a workaround, one may apply the patch from commit `211dfe9` manually.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/acm309/PutongOJ/commit/211dfe9ebf1c6618ce5396b0338de4f9b58071
- https://github.com/acm309/PutongOJ/releases/tag/v2.1.0-beta.1
- https://github.com/acm309/PutongOJ/security/advisories/GHSA-gj6h-73c5-xw6f
FAQ
What is CVE-2024-48920?
CVE-2024-48920 is a vulnerability with a CVSS score of 9.1 (CRITICAL). PutongOJ is online judging software. Prior to version 2.1.0-beta.1, unprivileged users can escalate privileges by constructing requests. This can lead to unauthorized access, enabling users to perform...
How severe is CVE-2024-48920?
CVE-2024-48920 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-48920?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.