Amazon Vulnerabilities and Affected Products
Vulnerabilities associated with data.all.
Products
Clear product- Amazon Athena ODBC driver6 vulnerabilities
- data.all5 vulnerabilities
- Amazon Redshift JDBC Driver2 vulnerabilities
- Fire TV Stick 3rd gen2 vulnerabilities
- WorkSpaces Client2 vulnerabilities
- Amazon Ion Dotnet1 vulnerability
- Amazon Music Player1 vulnerability
- Amazon Redshift ODBC Driver1 vulnerability
- Amazon Redshift Python Connector1 vulnerability
- Amazon WorkSpaces1 vulnerability
- Amazon.ApplicationLoadBalancer.Identity.AspNetCore Middleware1 vulnerability
- Amazon.IonDotnet1 vulnerability
- Amplify Studio1 vulnerability
- AppStream 2.0 Client1 vulnerability
- Aurora MySQL1 vulnerability
- AWS ALB Route Directive Adapter For Istio1 vulnerability
- AWS EFS CSI Driver1 vulnerability
- AWS SDK1 vulnerability
- aws-dataall1 vulnerability
- aws-load-balancer-controller1 vulnerability
- aws_alb_route_directive_adapter_for_istio1 vulnerability
- aws_client_vpn1 vulnerability
- Blink XT2 Sync Module firmware1 vulnerability
- Cloud Cam1 vulnerability
- DCV Client1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-52314MEDIUM | data.all admin user may access potentially sensitive data stored by producers via logsA data.all admin team member who has access to the customer-owned AWS Account where data.all is deployed may be able to extract user data from data.all application logs in data.all via CloudWatch log scanning for particular operations that interact with customer producer teams data. CWE-863Nov 9, 2024 | CVSS6.9v4.0 | EPSS0.393% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-52312MEDIUM | data.all authenticated users can perform restricted operations against DataSets and EnvironmentsDue to inconsistent authorization permissions, data.all may allow an external actor with an authenticated account to perform restricted operations against DataSets and Environments. CWE-863Nov 9, 2024 | CVSS5.3v4.0 | EPSS0.334% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-52313MEDIUM | data.all authenticated users can obtain incorrect object level authorizationsAn authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the parent Environment resource that the user otherwise would not able to fetch by directly querying the object via getEnvironment in data.all. CWE-639Nov 9, 2024 | CVSS5.3v4.0 | EPSS0.304% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-10953MEDIUM | data.all authenticated users can perform mutating update operations on persisted notification recordsAn authenticated data.all user is able to perform mutating UPDATE operations on persisted Notification records in data.all for group notifications that their user is not a member of. CWE-863Nov 9, 2024 | CVSS5.3v4.0 | EPSS0.299% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-52311MEDIUM | data.all does not invalidate authentication token upon user logoutAuthentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution of authorized API Requests until token is expired. CWE-613Nov 9, 2024 | CVSS5.3v4.0 | EPSS0.461% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |