CVE-2024-1682

MEDIUM

Unclaimed Amazon S3 Bucket - Info Disclosure

Title source: llm
STIX 2.1

Description

An unclaimed Amazon S3 bucket, 'codeconf', is referenced in an audio file link within the .rst documentation file. This bucket has been claimed by an external party. The use of this unclaimed S3 bucket could lead to data integrity issues, data leakage, availability problems, loss of trustworthiness, and potential further attacks if the bucket is used to host malicious content or as a pivot point for further attacks.

Scores

CVSS v3 4.3
EPSS 0.0011
EPSS Percentile 28.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-840
Status published
Products (1)
psf/psf/requests unspecified
Published Nov 14, 2024
Tracked Since Feb 18, 2026