GHSA-4fpg-j5mp-783g

Suggest an improvement
Source
https://github.com/advisories/GHSA-4fpg-j5mp-783g
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4fpg-j5mp-783g/GHSA-4fpg-j5mp-783g.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4fpg-j5mp-783g
Aliases
Published
2022-05-13T01:49:46Z
Modified
2024-09-13T16:06:21.237625Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N CVSS Calculator
  • 1.3 (Low) CVSS_V4 - CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U CVSS Calculator
Summary
Cloudtoken Insufficiently Protects Credentials
Details

Unauthenticated access to cloudtoken daemon on Linux via network from version 0.1.1 before version 0.1.24 allows attackers on the same subnet to gain temporary AWS credentials for the users' roles.

Database specific
{
    "nvd_published_at": "2018-08-10T15:29:00Z",
    "cwe_ids": [
        "CWE-522"
    ],
    "severity": "LOW",
    "github_reviewed": true,
    "github_reviewed_at": "2024-04-22T22:45:45Z"
}
References

Affected packages

PyPI / cloudtoken

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.1.1
Fixed
0.1.24

Affected versions

0.*
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.21
0.1.22
0.1.23

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4fpg-j5mp-783g/GHSA-4fpg-j5mp-783g.json"