PT-2023-31713 · Unknown · Sandbox Accounts For Events

Mahmoud0X00

·

Published

2023-12-22

·

Updated

2024-01-08

·

CVE-2023-50928

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Sandbox Accounts for Events versions prior to 1.1.0
Description The issue allows authenticated users to potentially claim and access empty AWS accounts by sending request payloads to the account API containing non-existent event ids and self-defined budget & duration. This issue only affects cleaned AWS accounts, and it is not possible to access AWS accounts in use or existing data/infrastructure.
Recommendations For versions prior to 1.1.0, update to version 1.1.0 to resolve the issue. As a temporary workaround, consider restricting access to the account API to minimize the risk of exploitation. Avoid using the API to claim empty AWS accounts with non-existent event ids until the issue is resolved.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2023-50928
GHSA-CG8W-7Q5V-G32R

Affected Products

Sandbox Accounts For Events