ZeroHour

CVE-2018-13390

CVSS 3.0
6.1 medium
EPSS
<1%p39
Published
()
Modified
Description

Unauthenticated access to cloudtoken daemon on Linux via network from version 0.1.1 before version 0.1.24 allows attackers on the same subnet to gain temporary AWS credentials for the users' roles.

Vendors
atlassian
Products
cloudtoken
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.