An authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the parent Environment resource that the user otherwise would not able to fetch by directly querying the object via getEnvironment in data.all.
Metrics
Affected Vendors & Products
References
History
Wed, 13 Nov 2024 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 09 Nov 2024 01:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Sat, 09 Nov 2024 01:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the parent Environment resource that the user otherwise would not able to fetch by directly querying the object via getEnvironment in data.all. | |
Title | data.all authenticated users can obtain incorrect object level authorizations | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: AMZN
Published: 2024-11-09T00:43:00.250Z
Updated: 2024-11-12T15:14:33.692Z
Reserved: 2024-11-06T21:02:34.355Z
Link: CVE-2024-52313
Vulnrichment
Updated: 2024-11-12T15:14:27.447Z
NVD
Status : Awaiting Analysis
Published: 2024-11-09T01:15:05.363
Modified: 2024-11-12T13:56:54.483
Link: CVE-2024-52313
Redhat
No data.