Amazon
Amazon Data.all: vulnerabilidades y CVE
Amazon Data.all tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-52314 | Media (6.9) | 0.40% | — | 9 nov 2024 | A data.all admin team member who has access to the customer-owned AWS Account where data.all is deployed may be able to extract user data from data.all application logs in data.all via CloudWatch log scanning for… |
| CVE-2024-52313 | Media (5.3) | 0.31% | — | 9 nov 2024 | An authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the parent Environment resource that the user otherwise would not able to fetch by directly querying the… |
| CVE-2024-52312 | Media (5.3) | 0.35% | — | 9 nov 2024 | Due to inconsistent authorization permissions, data.all may allow an external actor with an authenticated account to perform restricted operations against DataSets and Environments. |
| CVE-2024-52311 | Media (5.3) | 0.48% | — | 9 nov 2024 | Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution of authorized API Requests until token is expired. |
| CVE-2024-10953 | Media (5.3) | 0.31% | — | 9 nov 2024 | An authenticated data.all user is able to perform mutating UPDATE operations on persisted Notification records in data.all for group notifications that their user is not a member of. |