SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-34085

When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request

MEDIUM 4.3EPSS 0.47%

Does this matter?

Lower severity and a low EPSS score (0.47%). Track it; it rarely justifies an emergency change on its own.

Description

When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
0.47% probability · 39th percentile
CISA KEV
Not listed
Weakness
CWE-359
Affected
pingidentity/pingfederate
Source
responsible-disclosure@pingidentity.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.