High severity8.0NVD Advisory· Published Jun 28, 2023· Updated Jun 17, 2026
CVE-2023-36467
CVE-2023-36467
Description
AWS data.all is an open source development framework to help users build a data marketplace on Amazon Web Services. data.all versions 1.2.0 through 1.5.1 do not prevent remote code execution when a user injects Python commands into the ‘Template’ field when configuring a data pipeline. The issue can only be triggered by authenticated users. A fix for this issue is available in data.all version 1.5.2 and later. There is no recommended work around.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- awslabs/aws-dataallv5Range: >= 1.2.0, < 1.5.2
Patches
Vulnerability mechanics
References
4- github.com/awslabs/aws-dataall/pull/472nvdPatch
- github.com/awslabs/aws-dataall/security/advisories/GHSA-m922-chh7-8qcrnvdVendor Advisory
- github.com/awslabs/aws-dataall/releases/tag/v1.5.2nvdRelease Notes
- github.com/awslabs/aws-dataall/releases/tag/v1.5.4nvdRelease Notes
News mentions
0No linked articles in our index yet.