CVE-2018-15869 describes a vulnerability in HashiCorp Packer where AWS developers, by omitting the --owners flag when describing images via AWS CLI, risk unintentionally loading malicious Amazon Machine Images (AMIs) from the public catalog. This medium-severity vulnerability (CVSS 5.3) has a low attack complexity and can lead to a loss of integrity, as it allows for the loading of untrusted software. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.0CPE matchmatch criteria | cpe:2.3:a:hashicorp:packer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.