CVE-2018-15869
An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and therefore not properly validating source software per AWS recommended security best practices, may unintentionally load an undesired and potentially malicious Amazon Machine Image (AMI) from the uncurated public community AMI catalog.
- Affected products
- Aws, Aws Cli, Amazon Machine Image, Suse
- Hashicorp Packer
- < 1.3.0
- CVSS 3.0
- 5.3 MEDIUM
- EPSS
- 1.8% (76th percentile)
- Weakness
- CWE-732
- NVD status
- Modified
- Published
- 2018-08-25
CVE-2018-15869 at NVD
No indexed exploits for CVE-2018-15869 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2018-15869 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.