diff --git a/gems/Autolab/CVE-2024-49376.yml b/gems/Autolab/CVE-2024-49376.yml new file mode 100644 index 0000000000..eae632a6ce --- /dev/null +++ b/gems/Autolab/CVE-2024-49376.yml @@ -0,0 +1,33 @@ +--- +gem: Autolab +cve: 2024-49376 +ghsa: v46j-h43h-rwrm +url: https://github.com/autolab/Autolab/security/advisories/GHSA-v46j-h43h-rwrm +title: Autolab Misconfigured Reset Password Permissions +date: 2024-10-25 +description: | + ### Impact + For email-based accounts, users with insufficient privileges could reset and theoretically access privileged users' accounts by resetting their passwords. + + ### Patches + This is fixed in v3.0.1. + + ### Workarounds + No workarounds. + + ### For more information + If you have any questions or comments about this advisory: + + Open an issue in https://github.com/autolab/Autolab/ + Email us at [autolab-dev@andrew.cmu.edu](mailto:autolab-dev@andrew.cmu.edu) +cvss_v3: 8.8 +unaffected_versions: +- "< 3.0.0" +patched_versions: +- ">= 3.0.1" +related: + url: + - https://github.com/autolab/Autolab/security/advisories/GHSA-v46j-h43h-rwrm + - https://nvd.nist.gov/vuln/detail/CVE-2024-49376 + - https://github.com/autolab/Autolab/commit/301689ab5c5e39d13bab47b71eaf8998d04bcc9b + - https://github.com/advisories/GHSA-v46j-h43h-rwrm