Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pp3f-98qg-5g75

Опубликовано: 13 июл. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

aws-iam-authenticator allow-listed IAM identity may be able to modify their username, escalate privileges before v0.5.9

A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.

Пакеты

Наименование

sigs.k8s.io/aws-iam-authenticator

go
Затронутые версииВерсия исправления

< 0.5.9

0.5.9

EPSS

Процентиль: 54%
0.00313
Низкий

8.1 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.1
redhat
больше 3 лет назад

A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.

CVSS3: 8.1
nvd
больше 3 лет назад

A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.

suse-cvrf
больше 3 лет назад

Security update for aws-iam-authenticator

EPSS

Процентиль: 54%
0.00313
Низкий

8.1 High

CVSS3

Дефекты

CWE-20