Description
OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code execution (RCE) vulnerability was identified in the OpenLearnX code execution environment, allowing sandbox escape and arbitrary command execution. This issue has been patched in version 2.0.3.
Problem types
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-94: Improper Control of Generation of Code ('Code Injection')
CWE-250: Execution with Unnecessary Privileges
CWE-284: Improper Access Control
CWE-693: Protection Mechanism Failure
Product status
References
github.com/...LearnX/security/advisories/GHSA-8h25-q488-4hxw
github.com/...ommit/14765d7d1856d564747c55c5412e2f38feab079e
github.com/...4y/OpenLearnX/releases/tag/v2.0.3-security-fix