Skip to content

HTML Injection Vulnerability

Moderate
20wildmanj published GHSA-8qhp-jhhw-45r2 Nov 18, 2024

Package

bundler Autolab (RubyGems)

Affected versions

3.0.1

Patched versions

3.0.2

Description

Impact

There is an HTML injection vulnerability that can affect instructors and CAs on the grade submissions page.

Patches

Patched in version 3.0.2

Workarounds

No, there is a quick fix by editing line 589 on gradesheet.js.erb to take in feedback as text rather than html.

References

N/A

Severity

Moderate

CVE ID

CVE-2024-52585

Weaknesses

No CWEs

Credits