CVE-2018-13390

MEDIUM

cloudtoken 0.1.1-0.1.23 - Unauthenticated AWS Credential Exposure via Network Daemon Access

Title source: llm
STIX 2.1

Description

Unauthenticated access to cloudtoken daemon on Linux via network from version 0.1.1 before version 0.1.24 allows attackers on the same subnet to gain temporary AWS credentials for the users' roles.

References (1)

Core 1

Scores

CVSS v3 6.1
EPSS 0.0011
EPSS Percentile 28.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Details

Status published
Products (2)
atlassian/cloudtoken 0.1.1 - 0.1.24
pypi/cloudtoken 0.1.1 - 0.1.24PyPI
Published Aug 10, 2018
Tracked Since Feb 18, 2026