PT-2024-16661 · Amazon · Amazon Web Services

Noah-Paige

·

Published

2024-11-08

·

Updated

2025-10-14

·

CVE-2024-10953

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Amazon Web Services (AWS) (affected versions not specified)
Description The issue allows an authenticated data.all user to perform mutating UPDATE operations on persisted Notification records in data.all for group notifications that their user is not a member of.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-10953
GHSA-X4J5-JM65-VP5J

Affected Products

Amazon Web Services