Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-40427 | AWS data.all is an open source development framework to help users build a data marketplace on Amazon Web Services. data.all versions 1.2.0 through 1.5.1 do not prevent remote code execution when a user injects Python commands into the ‘Template’ field when configuring a data pipeline. The issue can only be triggered by authenticated users. A fix for this issue is available in data.all version 1.5.2 and later. There is no recommended work around. |
Wed, 06 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-11-06T17:17:18.002Z
Reserved: 2023-06-21T18:50:41.700Z
Link: CVE-2023-36467
Updated: 2024-08-02T16:45:57.043Z
Status : Modified
Published: 2023-06-28T14:15:09.967
Modified: 2024-11-21T08:09:46.387
Link: CVE-2023-36467
No data.
OpenCVE Enrichment
No data.
EUVD