An authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the parent Environment resource that the user otherwise would not able to fetch by directly querying the object via getEnvironment in data.all.
Metrics
Affected Vendors & Products
References
History
Wed, 13 Nov 2024 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 09 Nov 2024 01:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Sat, 09 Nov 2024 01:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the parent Environment resource that the user otherwise would not able to fetch by directly querying the object via getEnvironment in data.all. | |
Title | data.all authenticated users can obtain incorrect object level authorizations | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: AMZN
Published: 2024-11-09T00:43:00.250Z
Updated: 2024-11-12T15:14:33.692Z
Reserved: 2024-11-06T21:02:34.355Z
Link: CVE-2024-52313

Updated: 2024-11-12T15:14:27.447Z

Status : Awaiting Analysis
Published: 2024-11-09T01:15:05.363
Modified: 2024-11-12T13:56:54.483
Link: CVE-2024-52313

No data.