Vulnerability Change Records for CVE-2023-50928
Change History
New CVE Received by NIST 12/22/2023 4:15:08 PM
Action |
Type |
Old Value |
New Value |
Added |
CVSS V3.1 |
|
GitHub, Inc. AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
|
Added |
CWE |
|
GitHub, Inc. CWE-284
|
Added |
Description |
|
"Sandbox Accounts for Events" provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Authenticated users could potentially claim and access empty AWS accounts by sending request payloads to the account API containing non-existent event ids and self-defined budget & duration. This issue only affects cleaned AWS accounts, it is not possible to access AWS accounts in use or existing data/infrastructure. This issue has been patched in version 1.1.0.
|
Added |
Reference |
|
GitHub, Inc. https://github.com/awslabs/sandbox-accounts-for-events/commit/f30a0662f0a28734eb33c5868cccc1c319eb6e79 [No types assigned]
|
Added |
Reference |
|
GitHub, Inc. https://github.com/awslabs/sandbox-accounts-for-events/security/advisories/GHSA-cg8w-7q5v-g32r [No types assigned]
|
|