PT-2024-18218 · Amazon · Amazon S3
Published
2024-11-14
·
Updated
2024-11-22
·
CVE-2024-1682
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Amazon S3 (affected versions not specified)
Description
The issue concerns an unclaimed Amazon S3 bucket, 'codeconf', referenced in an audio file link within a documentation file. This bucket has been claimed by an external party, which could lead to data integrity issues, data leakage, availability problems, loss of trustworthiness, and potential further attacks if the bucket is used to host malicious content or as a pivot point for further attacks.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amazon S3