CVE-2024-42988

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Oct 9, 2024
Updated: Feb 10, 2025
CWE ID 284

Summary

CVE-2024-42988 is a vulnerability affecting CTFd versions 2.0.0 to 3.7.2. The issue stems from insufficient access controls in the ChallengeSolves API endpoint (/api/v1/challenges/<challenge id>/solves). This vulnerability enables authenticated users to access a list of users who have solved a specific challenge, disregarding Account Visibility settings. The flaw has been rectified in versions 3.7.3 and above.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share