Amazon / Data.all
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-52314 | data.all admin user may access potentially sensitive data stored by producers via logs | MEDIUM | 6.9 | Nov 9, 2024 |
| CVE-2024-52312 | data.all authenticated users can perform restricted operations against DataSets and Environments | MEDIUM | 5.3 | Nov 9, 2024 |
| CVE-2024-52313 | data.all authenticated users can obtain incorrect object level authorizations | MEDIUM | 5.3 | Nov 9, 2024 |
| CVE-2024-10953 | data.all authenticated users can perform mutating update operations on persisted notification records | MEDIUM | 5.3 | Nov 9, 2024 |
| CVE-2024-52311 | data.all does not invalidate authentication token upon user logout | MEDIUM | 5.3 | Nov 9, 2024 |
Showing 1 to 5 of 5 CVEs