PT-2023-31713 · Unknown · Sandbox Accounts For Events
Mahmoud0X00
·
Publicado
2023-12-22
·
Atualizado
2024-01-08
·
CVE-2023-50928
CVSS v3.1
7.1
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Sandbox Accounts for Events versions prior to 1.1.0
Description
The issue allows authenticated users to potentially claim and access empty AWS accounts by sending request payloads to the account API containing non-existent event ids and self-defined budget & duration. This issue only affects cleaned AWS accounts, and it is not possible to access AWS accounts in use or existing data/infrastructure.
Recommendations
For versions prior to 1.1.0, update to version 1.1.0 to resolve the issue. As a temporary workaround, consider restricting access to the account API to minimize the risk of exploitation. Avoid using the API to claim empty AWS accounts with non-existent event ids until the issue is resolved.
Exploit
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sandbox Accounts For Events