Cross Site Request Forgery at refreshing watch list for courses in autolab/autolab


Reported on

May 13th 2022


Hi there autolab maintainers, there is a CRSF in autolab source code in refreshing watch list due to usage of GET method.

Proof of Concept

  1. Install a local instance of autolab and create a course
  2. Access the link /courses/<course-name>/metrics/refresh_watchlist_instances and see that any previously added watchlist is archieved.




We are processing your report and will contact the autolab team within 24 hours. a year ago
We have contacted a member of the autolab team and are waiting to hear back a year ago
autolab/autolab maintainer validated this vulnerability a year ago
justinp09010 has been awarded the disclosure bounty
The fix bounty is now up for grabs
The researcher's credibility has increased: +7
We have sent a fix follow up to the autolab team. We will try again in 7 days. a year ago
Joey Wildman marked this as fixed in 2.8+ with commit 151aa1 a year ago
Joey Wildman has been awarded the fix bounty
This vulnerability will not receive a CVE
routes.rb#L83 has been validated
to join this conversation