AWS Loom 1.7.0 之前的版本中,OAuth2 发现处理存在服务端请求伪造(SSRF)漏洞。攻击者通过构造恶意的发现文档地址(在注册工具服务器或配置为委派认证的远程代理时提供),可能使经过身份验证的远程用户获取部署中其他用户的访问令牌,并导致应用程序向任意内部网络位置发起请求。 要修复此问题,用户应升级至 1.7.0 或更高版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103956 | 10.0 CRITICAL | Missing authentication for critical function in Loom for AWS |
| CVE-2026-104019 | 9.0 CRITICAL | OS command injection in the Studio Space startup validation script in Amazon SageMaker Dis |
| CVE-2026-103958 | 7.6 HIGH | Server-side request forgery in the tool server and remote agent connection handling in Loo |
No comments yet