Unauthenticated access to cloudtoken daemon on Linux via network from version 0.1.1 before version 0.1.24 allows attackers on the same subnet to gain temporary AWS credentials for the users' roles.
References
Link | Resource |
---|---|
https://bitbucket.org/atlassian/cloudtoken/wiki/CVE-2018-13390%20-%20Exposed%20credentials%20in%20daemon%20mode%20on%20Linux | Mitigation Third Party Advisory |
Configurations
Information
Published : 2018-08-10 08:29
Updated : 2019-10-02 17:03
NVD link : CVE-2018-13390
Mitre link : CVE-2018-13390
JSON object : View
CWE
Products Affected
atlassian
- cloudtoken