Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-15869

Опубликовано: 25 авг. 2018
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and therefore not properly validating source software per AWS recommended security best practices, may unintentionally load an undesired and potentially malicious Amazon Machine Image (AMI) from the uncurated public community AMI catalog.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hashicorp:packer:*:*:*:*:*:*:*:*
Версия до 1.3.0 (исключая)

EPSS

Процентиль: 67%
0.00553
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 7 лет назад

An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and therefore not properly validating source software per AWS recommended security best practices, may unintentionally load an undesired and potentially malicious Amazon Machine Image (AMI) from the uncurated public community AMI catalog.

CVSS3: 5.3
redhat
больше 7 лет назад

An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and therefore not properly validating source software per AWS recommended security best practices, may unintentionally load an undesired and potentially malicious Amazon Machine Image (AMI) from the uncurated public community AMI catalog.

CVSS3: 5.3
debian
больше 7 лет назад

An Amazon Web Services (AWS) developer who does not specify the --owne ...

suse-cvrf
около 6 лет назад

Security update for aws-cli

suse-cvrf
около 7 лет назад

Recommended update for aws-cli, python-boto3, python-botocore, python-s3transfer

EPSS

Процентиль: 67%
0.00553
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-732