CVE-2024-52314

Source
https://cve.org/CVERecord?id=CVE-2024-52314
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-52314.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-52314
Aliases
  • GHSA-p2h8-r28g-5q6h
Published
2024-11-09T00:43:10Z
Modified
2026-08-12T03:51:32Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
data.all admin user may access potentially sensitive data stored by producers via logs
Details

A data.all admin team member who has access to the customer-owned AWS Account where data.all is deployed may be able to extract user data from data.all application logs in data.all via CloudWatch log scanning for particular operations that interact with customer producer teams data.

Database specific
{
    "cna_assigner": "AMZN",
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/52xxx/CVE-2024-52314.json"
}
References

Affected packages

Git / github.com/data-dot-all/dataall

Affected ranges

Type
GIT
Repo
https://github.com/data-dot-all/dataall
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:amazon:data.all:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.0.0"
        },
        {
            "last_affected": "2.6.0"
        },
        {
            "fixed": "2.6.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.5.6
v1.6.0
v1.6.1
v1.6.2
v2.*
v2.0.0
v2.1.0
v2.2.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-52314.json"