Skip to main content

CVE-2023-50928

7.1
HIGHCVSS v3.1 Base Score
0.06%
LOW RiskEPSS (20th percentile)

"Sandbox Accounts for Events" provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Authenticated users could potentially claim and access empty AWS accounts by sending request payloads to the account API containing non-existent event ids and self-defined budget & duration. This issue only affects cleaned AWS accounts, it is not possible to access AWS accounts in use or existing data/infrastructure. This issue has been patched in version 1.1.0.

Published: 12/22/2023
Modified: 11/21/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.1HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

EPSS Score (Exploitation Probability)

0.06%LOW Exploitation Risk
20th percentile

This vulnerability has a 0.06% probability of being exploited in the next 30 days, ranking higher than 20% of all scored CVEs.

Related Vulnerabilities