aws.amazon.comVendor advisory
https://aws.amazon.com/security/security-bulletins/AWS-2024-013 CVE-2024-52313
MEDIUM
data.all authenticated users can obtain incorrect object level authorizations
Record summary
CVE-2024-52313 has a selected CVSS score of 5.3 (medium).
Description
An authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the parent Environment resource that the user otherwise would not able to fetch by directly querying the object via getEnvironment in data.all.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 12, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
data.allBrowse amazon / data.allDefault status: unaffected | CVE List | 1.0.0 to ≤ 2.6.0 | affected |
References
3github.compatch
https://github.com/data-dot-all/dataall/releases/tag/v2.6.1 github.comThird-party advisory
https://github.com/data-dot-all/dataall/security/advisories/GHSA-hx8q-7wxv-6c7c