Insufficiently Protected Credentials
CVE-2018-13390
Summary
Unauthenticated access to cloudtoken daemon on Linux via network from versions 0.1.1 through 0.1.23 allows attackers on the same subnet to gain temporary AWS credentials for the users' roles.
- LOW
- ADJACENT_NETWORK
- LOW
- CHANGED
- NONE
- NONE
- LOW
- NONE
CWE-522 - Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Advisory Timeline
- Published