Due to inconsistent authorization permissions, data.all may allow an external actor with an authenticated account to perform restricted operations against DataSets and Environments.
Solution:
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://aws.amazon.com/security/security-bulletins/AWS-2024-013 | vendor advisory |
https://github.com/data-dot-all/dataall/security/advisories/GHSA-676j-g6g5-chj9 | third party advisory |