CVE-2024-10953
CVSS V2 None
CVSS V3 None
Description
An authenticated data.all user is able to perform mutating UPDATE operations on persisted Notification records in data.all for group notifications that their user is not a member of.
Overview
- CVE ID
- CVE-2024-10953
- Assigner
- AMZN
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-11-09T00:42:55.584Z
- Last Modified Date
- 2024-11-09T00:55:56.915Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://aws.amazon.com/security/security-bulletins/AWS-2024-013 | vendor-advisory |
https://github.com/data-dot-all/dataall/security/advisories/GHSA-x4j5-jm65-vp5j | third-party-advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-10953 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-10953 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-11-09 13:12:54 | Added to TrackCVE |