CVE-2024-1682 Details
Description
An unclaimed Amazon S3 bucket, 'codeconf', is referenced in an audio file link within the .rst documentation file. This bucket has been claimed by an external party. The use of this unclaimed S3 bucket could lead to data integrity issues, data leakage, availability problems, loss of trustworthiness, and potential further attacks if the bucket is used to host malicious content or as a pivot point for further attacks.
A vulnerability exists due to the use of an unclaimed Amazon S3 bucket named 'codeconf' in an audio file link within the documentation of the 'psf/requests' repository. This bucket has been claimed by an external party. The vulnerability could lead to various issues, including data integrity problems, data leakage, availability disruptions, loss of trustworthiness, and potential further attacks if the bucket is used to host malicious content or as a pivot point for additional attacks.
The unclaimed S3 bucket has been removed from the documentation to prevent any future traffic.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 14, 2024CISA-ADP
Assessed Nov 18, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/psf/requests/commit/6106a63eb6c0fa490efa73d44388ac25b1b08af4 | [email protected] | Source CodeVendor |
| https://huntr.com/bounties/4da5ded5-b59b-4ece-8812-46a4329e446c | [email protected] | ExploitIssue TrackingTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-840 | Business Logic Errors | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| psf requests | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 18, 2024 | CVE Modified | CISA-ADP |
| Nov 14, 2024 | New CVE Received | [email protected] |
Volerion