CVE-2024-52314

CVSS 3.1 Score 4.9 of 10 (medium)

Details

Published Nov 9, 2024
Updated: Nov 12, 2024
CWE ID 863

Summary

CVE-2024-52314 is a newly disclosed vulnerability affecting the data.all application. This issue allows a data.all admin team member with access to the related AWS account to extract user data from the application logs through CloudWatch log scanning. Specifically, the vulnerability is related to certain operations that interact with customer producer team data. The implications of this vulnerability are significant as it may lead to unintended data exposure. It's crucial for organizations using data.all to review their access control policies and limit permissions to minimize potential risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share