When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Ping Identity

Published: 2023-10-25T02:03:56.433Z

Updated: 2023-10-25T02:03:56.433Z

Reserved: 2023-07-25T20:13:14.876Z


Link: CVE-2023-34085

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-10-25T18:17:28.010

Modified: 2023-10-31T15:19:06.623


Link: CVE-2023-34085

JSON object: View

cve-icon Redhat Information

No data.