Skip to content

Commit 5cf5259

Browse files
committed
GHSA SYNC: 1 brand new advisory
1 parent e7530e9 commit 5cf5259

File tree

1 file changed

+33
-0
lines changed

1 file changed

+33
-0
lines changed

gems/Autolab/CVE-2024-49376.yml

Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
---
2+
gem: Autolab
3+
cve: 2024-49376
4+
ghsa: v46j-h43h-rwrm
5+
url: https://github.com/autolab/Autolab/security/advisories/GHSA-v46j-h43h-rwrm
6+
title: Autolab Misconfigured Reset Password Permissions
7+
date: 2024-10-25
8+
description: |
9+
### Impact
10+
For email-based accounts, users with insufficient privileges could reset and theoretically access privileged users' accounts by resetting their passwords.
11+
12+
### Patches
13+
This is fixed in v3.0.1.
14+
15+
### Workarounds
16+
No workarounds.
17+
18+
### For more information
19+
If you have any questions or comments about this advisory:
20+
21+
Open an issue in https://github.com/autolab/Autolab/
22+
Email us at [[email protected]](mailto:[email protected])
23+
cvss_v3: 8.8
24+
unaffected_versions:
25+
- "< 3.0.0"
26+
patched_versions:
27+
- ">= 3.0.1"
28+
related:
29+
url:
30+
- https://github.com/autolab/Autolab/security/advisories/GHSA-v46j-h43h-rwrm
31+
- https://nvd.nist.gov/vuln/detail/CVE-2024-49376
32+
- https://github.com/autolab/Autolab/commit/301689ab5c5e39d13bab47b71eaf8998d04bcc9b
33+
- https://github.com/advisories/GHSA-v46j-h43h-rwrm

0 commit comments

Comments
 (0)