When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request
2023-10-25T18:17:28.010
2024-11-21T08:06:30.577
Modified
CVSSv3.1: 2.6 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | pingidentity | pingfederate | ≤ 11.3.0 | Yes |