Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability exists in Classroom 50, an open-source tool for managing programming assignments, that could allow a student to overwrite critical system files or execute code on a teacher's computer. This occurs when the tool processes student repositories, as it incorrectly handles symbolic links within assignment files. While the tool has been updated to address this issue, a workaround involves avoiding the processing of untrusted student submissions or conducting the operation in an isolated environment.
- Students could compromise teacher's systems.
- Teacher's administrative access is at risk.
- Confirm relevance and exposure of this tool.
Attack Path
How an attacker could exploit the issue
An attacker, acting as a student, could craft a malicious assignment repository containing a symlink disguised as an autograde artifact. When a teacher uses the `gh teacher download` command to retrieve assignments, this symlink could trick the tool into writing arbitrary data, such as malicious code, to sensitive files on the teacher's system. This could grant the attacker elevated privileges and control over the teacher's environment and organization.
- Requires student control of assignment repository.
- Triggered by teacher downloading assignments.
- Risk of arbitrary file write and code execution.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow a student to overwrite arbitrary files on a teacher's system by providing specially crafted symlinks within their assignment repository. When the teacher uses the `gh teacher download` command, these symlinks could redirect file writes to critical system files or SSH authorized keys, potentially leading to the execution of malicious code with the teacher's elevated privileges.
- Teacher system files and credentials.
- Writing through symlinks in student repos.
- Arbitrary file write leading to code execution.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Classroom 50 tool's `gh teacher download` command is vulnerable to arbitrary file writes, potentially leading to code execution as the teacher. This issue primarily impacts the application owner or the platform team responsible for managing and deploying Classroom 50, as well as security teams who oversee the integrity of teacher accounts and systems. The first practical step is to identify all instances of Classroom 50, assess their exposure, and confirm the responsible team for remediation.
- Identify Classroom 50 instances.
- Verify teacher account exposure.
- Plan remediation and vendor coordination.