CVE-2024-52312: Amazon Data.all
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
Due to inconsistent authorization permissions, data.all may allow an external actor with an authenticated account to perform restricted operations against DataSets and Environments.
Affected products
- Amazon Data.all: from 1.0.0, before 2.6.1 (fixed in 2.6.1)
Published 2024-11-09. Last modified 2026-06-17.