CVE-2023-36467
AWS data.all vulnerable to RCE through user injection of Python Commands
Severity Score
8.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
AWS data.all is an open source development framework to help users build a data marketplace on Amazon Web Services. data.all versions 1.2.0 through 1.5.1 do not prevent remote code execution when a user injects Python commands into the ‘Template’ field when configuring a data pipeline. The issue can only be triggered by authenticated users. A fix for this issue is available in data.all version 1.5.2 and later. There is no recommended work around.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-06-21 CVE Reserved
- 2023-06-28 CVE Published
- 2024-07-30 EPSS Updated
- 2024-11-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/awslabs/aws-dataall/releases/tag/v1.5.2 | Release Notes | |
https://github.com/awslabs/aws-dataall/releases/tag/v1.5.4 | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/awslabs/aws-dataall/pull/472 | 2023-07-07 |
URL | Date | SRC |
---|---|---|
https://github.com/awslabs/aws-dataall/security/advisories/GHSA-m922-chh7-8qcr | 2023-07-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Amazon Search vendor "Amazon" | Aws-dataall Search vendor "Amazon" for product "Aws-dataall" | >= 1.2.0 <= 1.5.1 Search vendor "Amazon" for product "Aws-dataall" and version " >= 1.2.0 <= 1.5.1" | - |
Affected
|