CVE-2018-13390: Atlassian Cloudtoken
Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.
Unauthenticated access to cloudtoken daemon on Linux via network from version 0.1.1 before version 0.1.24 allows attackers on the same subnet to gain temporary AWS credentials for the users' roles.
Affected products
- Atlassian Cloudtoken: from 0.1.1, before 0.1.24 (fixed in 0.1.24)
Published 2018-08-10. Last modified 2026-06-17.