CVE-2024-1682
Last modified
CVE-2024-1682 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. An unclaimed Amazon S3 bucket, 'codeconf', is referenced in an audio file link within the .rst documentation file. This bucket has been claimed by an external party. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
An unclaimed Amazon S3 bucket, 'codeconf', is referenced in an audio file link within the .rst documentation file. This bucket has been claimed by an external party. The use of this unclaimed S3 bucket could lead to data integrity issues, data leakage, availability problems, loss of trustworthiness, and potential further attacks if the bucket is used to host malicious content or as a pivot point for further attacks.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-1682?
How severe is CVE-2024-1682?
How do I fix CVE-2024-1682?
Are you affected by CVE-2024-1682?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
