CVE-2023-36467
Last modified
CVE-2023-36467 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. AWS data.all is an open source development framework to help users build a data marketplace on Amazon Web Services. data.all versions 1.2.0 through 1.5.1 do not prevent remote code execution when a user injects Python commands into the ‘Template’ field when configuring a data pipeline. EPSS estimates a 1.03% chance of exploitation in the next 30 days.
Description
AWS data.all is an open source development framework to help users build a data marketplace on Amazon Web Services. data.all versions 1.2.0 through 1.5.1 do not prevent remote code execution when a user injects Python commands into the ‘Template’ field when configuring a data pipeline. The issue can only be triggered by authenticated users. A fix for this issue is available in data.all version 1.5.2 and later. There is no recommended work around.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Amazon | Aws-Dataall | >= 1.2.0, <= 1.5.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-36467?
How severe is CVE-2023-36467?
How do I fix CVE-2023-36467?
Are you affected by CVE-2023-36467?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
