CVE-2024-42988
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Oct 9, 2024
Updated: Feb 10, 2025
CWE ID 284
Summary
CVE-2024-42988 is a vulnerability affecting CTFd versions 2.0.0 to 3.7.2. The issue stems from insufficient access controls in the ChallengeSolves API endpoint (/api/v1/challenges/<challenge id>/solves). This vulnerability enables authenticated users to access a list of users who have solved a specific challenge, disregarding Account Visibility settings. The flaw has been rectified in versions 3.7.3 and above.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.