An unclaimed Amazon S3 bucket, 'codeconf', is referenced in an audio file link within the .rst documentation file. This bucket has been claimed by an external party. The use of this unclaimed S3 bucket could lead to data integrity issues, data leakage, availability problems, loss of trustworthiness, and potential further attacks if the bucket is used to host malicious content or as a pivot point for further attacks.
History

Fri, 22 Nov 2024 14:00:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 18 Nov 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Psf
Psf psf-requests
CPEs cpe:2.3:a:psf:psf-requests:*:*:*:*:*:*:*:*
Vendors & Products Psf
Psf psf-requests
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Nov 2024 17:45:00 +0000

Type Values Removed Values Added
Description An unclaimed Amazon S3 bucket, 'codeconf', is referenced in an audio file link within the .rst documentation file. This bucket has been claimed by an external party. The use of this unclaimed S3 bucket could lead to data integrity issues, data leakage, availability problems, loss of trustworthiness, and potential further attacks if the bucket is used to host malicious content or as a pivot point for further attacks.
Title Unclaimed S3 Bucket Reference in psf/requests Documentation
Weaknesses CWE-840
References
Metrics cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2024-11-18T20:28:22.779Z

Reserved: 2024-02-20T19:18:03.562Z

Link: CVE-2024-1682

cve-icon Vulnrichment

Updated: 2024-11-18T20:23:36.350Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-14T18:15:18.193

Modified: 2024-11-18T21:35:03.980

Link: CVE-2024-1682

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-11-14T17:32:13Z

Links: CVE-2024-1682 - Bugzilla