Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-37293

Опубликовано: 11 июн. 2024
Источник: nvd
CVSS3: 7.5
CVSS3: 7.8
EPSS Низкий

Описание

The AWS Deployment Framework (ADF) is a framework to manage and deploy resources across multiple AWS accounts and regions within an AWS Organization. ADF allows for staged, parallel, multi-account, cross-region deployments of applications or resources via the structure defined in AWS Organizations while taking advantage of services such as AWS CodePipeline, AWS CodeBuild, and AWS CodeCommit to alleviate the heavy lifting and management compared to a traditional CI/CD setup. ADF contains a bootstrap process that is responsible to deploy ADF's bootstrap stacks to facilitate multi-account cross-region deployments. The ADF bootstrap process relies on elevated privileges to perform this task. Two versions of the bootstrap process exist; a code-change driven pipeline using AWS CodeBuild and an event-driven state machine using AWS Lambda. If an actor has permissions to change the behavior of the CodeBuild project or the Lambda function, they would be able to escalate their privileges.

Prior

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:amazon:aws_deployment_framework:*:*:*:*:*:*:*:*
Версия до 4.0.0 (исключая)

EPSS

Процентиль: 36%
0.00152
Низкий

7.5 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-266
NVD-CWE-Other

EPSS

Процентиль: 36%
0.00152
Низкий

7.5 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-266
NVD-CWE-Other
Уязвимость CVE-2024-37293