CVE-2024-1682
Public on 2024-11-14
Modified on 2024-11-26
Description
An unclaimed Amazon S3 bucket, 'codeconf', is referenced in an audio file link within the .rst documentation file. This bucket has been claimed by an external party. The use of this unclaimed S3 bucket could lead to data integrity issues, data leakage, availability problems, loss of trustworthiness, and potential further attacks if the bucket is used to host malicious content or as a pivot point for further attacks.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 1 | aws-cfn-bootstrap | No Fix Planned | ||
Amazon Linux 2 - Core | aws-cfn-bootstrap | Not Affected | ||
Amazon Linux 1 | python-botocore | No Fix Planned | ||
Amazon Linux 1 | python-pip | No Fix Planned | ||
Amazon Linux 1 | python-requests | No Fix Planned | ||
Amazon Linux 2 - Core | python-requests | Not Affected | ||
Amazon Linux 2023 | python-requests | Not Affected |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 4.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |
NVD | CVSSv3 | 4.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |