CVE-2024-42988

Lack of access control in ChallengeSolves (/api/v1/challenges/<challenge id>/solves) of CTFd v2.0.0 - v3.7.2 allows authenticated users to retrieve a list of users who have solved the challenge, regardless of the Account Visibility settings. The issue is fixed in v3.7.3+.
Configurations

No configuration.

History

10 Feb 2025, 23:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
CWE CWE-284

10 Oct 2024, 12:51

Type Values Removed Values Added
Summary
  • (es) La falta de control de acceso en ChallengeSolves (/api/v1/challenges//solves) de CTFd v2.0.0 - v3.7.2 permite que los usuarios autenticados recuperen una lista de usuarios que han resuelto el desafío, independientemente de la configuración de Visibilidad de la cuenta. El problema se solucionó en la versión v3.7.3+.

09 Oct 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-09 17:15

Updated : 2025-02-10 23:15


NVD link : CVE-2024-42988

Mitre link : CVE-2024-42988

CVE.ORG link : CVE-2024-42988


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control