CVE-2024-1682

Public on 2024-11-14
Modified on 2024-11-26
Description
An unclaimed Amazon S3 bucket, 'codeconf', is referenced in an audio file link within the .rst documentation file. This bucket has been claimed by an external party. The use of this unclaimed S3 bucket could lead to data integrity issues, data leakage, availability problems, loss of trustworthiness, and potential further attacks if the bucket is used to host malicious content or as a pivot point for further attacks.
Severity
Medium severity
Medium
CVSS v3 Base Score
4.3
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 aws-cfn-bootstrap No Fix Planned
Amazon Linux 2 - Core aws-cfn-bootstrap Not Affected
Amazon Linux 1 python-botocore No Fix Planned
Amazon Linux 1 python-pip No Fix Planned
Amazon Linux 1 python-requests No Fix Planned
Amazon Linux 2 - Core python-requests Not Affected
Amazon Linux 2023 python-requests Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
NVD CVSSv3 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N