Lucene search

K
gitlabHttps://gitlab.com/gitlab-org/security-products/gemnasium-dbGITLAB-20F5DC32EC5578680EC420257AD32D10
HistoryNov 16, 2023 - 12:00 a.m.

S3 Bucket can lead to spread of malicious R package

2023-11-1600:00:00
https://gitlab.com/gitlab-org/security-products/gemnasium-db
gitlab.com
1
s3 bucket
malicious
r package
h2o
url
attacker
software

7.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

6.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.5%

H2O included a reference to an S3 bucket that no longer existed allowing an attacker to take over the S3 bucket URL.

7.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

6.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.5%

Related for GITLAB-20F5DC32EC5578680EC420257AD32D10