PT-2024-18218 · Amazon · Amazon S3

Published

2024-11-14

·

Updated

2024-11-18

·

CVE-2024-1682

CVSS v3.1
4.3
VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Name of the Vulnerable Software and Affected Versions:

Amazon S3 (affected versions not specified)

Description:

The issue concerns an unclaimed Amazon S3 bucket, 'codeconf', referenced in an audio file link within a documentation file. This bucket has been claimed by an external party, which could lead to data integrity issues, data leakage, availability problems, loss of trustworthiness, and potential further attacks if the bucket is used to host malicious content or as a pivot point for further attacks.

Recommendations:

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-1682

Affected Products

Amazon S3