CVE-2023-36467

    Dashboard / Vulnerabilities / CVE-2023-36467

    CVE-2023-36467

    Published: 28 Jun 2023Last Modified: 12 Aug 2026

    Summary: AWS data.all vulnerable to RCE through user injection of Python Commands

    Details: AWS data.all is an open source development framework to help users build a data marketplace on Amazon Web Services. data.all versions 1.2.0 through 1.5.1 do not prevent remote code execution when a user injects Python commands into the ‘Template’ field when configuring a data pipeline. The issue can only be triggered by authenticated users. A fix for this issue is available in data.all version 1.5.2 and later. There is no recommended work around.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 4ecfd0f1b32917d7c5dd80fdf5fa167abd7c75d0

    Affected versions

    v1.5.3
    v1.5.2
    v1.5.1
    v1.5.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-36467 | CVE-DB