Unclaimed S3 Bucket Reference in psf/requests Documentation
Published Nov 14, 2024
4.3
MEDIUMCVSS 3.1
EPSS 0.39%
Description
An unclaimed Amazon S3 bucket, 'codeconf', is referenced in an audio file link within the .rst documentation file. This bucket has been claimed by an external party. The use of this unclaimed S3 bucket could lead to data integrity issues, data leakage, availability problems, loss of trustworthiness, and potential further attacks if the bucket is used to host malicious content or as a pivot point for further attacks.
Affected products
-
- Version unspecifiedStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Psf | Psf/requests | n/a |
|
No data.
-
- Version 0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Psf | Psf-Requests | n/a |
|
Red Hat Ansible Automation Platform 2
python3.11-requests
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Automation Platform 2 | python3.11-requests | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (7)
- https://access.redhat.com/security/cve/CVE-2024-1682 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2326318 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-17416 Advisory
- https://github.com/psf/requests/commit/6106a63eb6c0fa490efa73d44388ac25b1b08af4
- https://huntr.com/bounties/4da5ded5-b59b-4ece-8812-46a4329e446c
- https://nvd.nist.gov/vuln/detail/CVE-2024-1682
- https://www.cve.org/CVERecord?id=CVE-2024-1682
Change history (0)
No recorded changes yet.