An authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the parent Environment resource that the user otherwise would not able to fetch by directly querying the object via getEnvironment in data.all.
Solution:
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://aws.amazon.com/security/security-bulletins/AWS-2024-013 | vendor advisory |
https://github.com/data-dot-all/dataall/security/advisories/GHSA-hx8q-7wxv-6c7c | third party advisory |