Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-15869

Опубликовано: 14 авг. 2018
Источник: redhat
CVSS3: 5.3

Описание

An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and therefore not properly validating source software per AWS recommended security best practices, may unintentionally load an undesired and potentially malicious Amazon Machine Image (AMI) from the uncurated public community AMI catalog.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7awscliNot affected
Red Hat Enterprise Linux 8awscliNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1623095awscli: Allows loading of an undesired AMI by setting similar image properties

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 8 лет назад

An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and therefore not properly validating source software per AWS recommended security best practices, may unintentionally load an undesired and potentially malicious Amazon Machine Image (AMI) from the uncurated public community AMI catalog.

CVSS3: 5.3
nvd
почти 8 лет назад

An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and therefore not properly validating source software per AWS recommended security best practices, may unintentionally load an undesired and potentially malicious Amazon Machine Image (AMI) from the uncurated public community AMI catalog.

CVSS3: 5.3
debian
почти 8 лет назад

An Amazon Web Services (AWS) developer who does not specify the --owne ...

suse-cvrf
больше 6 лет назад

Security update for aws-cli

suse-cvrf
больше 7 лет назад

Recommended update for aws-cli, python-boto3, python-botocore, python-s3transfer

5.3 Medium

CVSS3