An authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the parent Environment resource that the user otherwise would not able to fetch by directly querying the object via getEnvironment in data.all.
History

Wed, 13 Nov 2024 08:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 09 Nov 2024 01:30:00 +0000


Sat, 09 Nov 2024 01:00:00 +0000

Type Values Removed Values Added
Description An authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the parent Environment resource that the user otherwise would not able to fetch by directly querying the object via getEnvironment in data.all.
Title data.all authenticated users can obtain incorrect object level authorizations
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published: 2024-11-09T00:43:00.250Z

Updated: 2024-11-12T15:14:33.692Z

Reserved: 2024-11-06T21:02:34.355Z

Link: CVE-2024-52313

cve-icon Vulnrichment

Updated: 2024-11-12T15:14:27.447Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-09T01:15:05.363

Modified: 2024-11-12T13:56:54.483

Link: CVE-2024-52313

cve-icon Redhat

No data.