PT-2023-31713 · Unknown · Sandbox Accounts For Events

Mahmoud0X00

·

Publicado

2023-12-22

·

Atualizado

2024-01-08

·

CVE-2023-50928

CVSS v3.1

7.1

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Sandbox Accounts for Events versions prior to 1.1.0
Description The issue allows authenticated users to potentially claim and access empty AWS accounts by sending request payloads to the account API containing non-existent event ids and self-defined budget & duration. This issue only affects cleaned AWS accounts, and it is not possible to access AWS accounts in use or existing data/infrastructure.
Recommendations For versions prior to 1.1.0, update to version 1.1.0 to resolve the issue. As a temporary workaround, consider restricting access to the account API to minimize the risk of exploitation. Avoid using the API to claim empty AWS accounts with non-existent event ids until the issue is resolved.

Exploit

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-50928
GHSA-CG8W-7Q5V-G32R

Produtos afetados

Sandbox Accounts For Events