{"id":"CVE-2023-36467","summary":"AWS data.all vulnerable to RCE through user injection of Python Commands","details":"AWS data.all is an open source development framework to help users build a data marketplace on Amazon Web Services. data.all versions 1.2.0 through 1.5.1 do not prevent remote code execution when a user injects Python commands into the ‘Template’ field when configuring a data pipeline. The issue can only be triggered by authenticated users. A fix for this issue is available in data.all version 1.5.2 and later. There is no recommended work around.","aliases":["GHSA-m922-chh7-8qcr"],"modified":"2026-08-12T03:51:25.748453561Z","published":"2023-06-28T13:55:06.163Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-94"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/36xxx/CVE-2023-36467.json"},"references":[{"type":"WEB","url":"https://github.com/awslabs/aws-dataall/releases/tag/v1.5.2"},{"type":"WEB","url":"https://github.com/awslabs/aws-dataall/releases/tag/v1.5.4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/36xxx/CVE-2023-36467.json"},{"type":"ADVISORY","url":"https://github.com/awslabs/aws-dataall/security/advisories/GHSA-m922-chh7-8qcr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-36467"},{"type":"FIX","url":"https://github.com/awslabs/aws-dataall/pull/472"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/data-dot-all/dataall","events":[{"introduced":"4ecfd0f1b32917d7c5dd80fdf5fa167abd7c75d0"},{"fixed":"3340610adb1f1897b3e8251f1b9b58b7ca578a90"},{"fixed":"fa45abd0b2af1b97c4f677354c5eed4d3de3d8c9"}],"database_specific":{"extracted_events":[{"introduced":"1.2.0"},{"last_affected":"1.5.1"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:amazon:aws-dataall:*:*:*:*:*:*:*:*"}}],"versions":["v1.5.3","v1.5.2","v1.5.1","v1.5.0","v1.4.3","v1.4.2","v1.4.1","v1.4.0","v1.3.1","v1.3.0","v1.2.3","v1.2.2","v1.2.1","v1.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-36467.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}