PT-2024-18218 · Amazon · Amazon S3
Published
2024-11-14
·
Updated
2024-11-18
·
CVE-2024-1682
CVSS v3.1
4.3
Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |
Weakness Enumeration
Related Identifiers
Affected Products
Amazon S3
Published
2024-11-14
·
Updated
2024-11-18
·
CVE-2024-1682
4.3
Medium
Base vector | Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Amazon S3 (affected versions not specified)
Description:
The issue concerns an unclaimed Amazon S3 bucket, 'codeconf', referenced in an audio file link within a documentation file. This bucket has been claimed by an external party, which could lead to data integrity issues, data leakage, availability problems, loss of trustworthiness, and potential further attacks if the bucket is used to host malicious content or as a pivot point for further attacks.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.