在 Loom for AWS 1.7.0 版本之前,工具服务器(tool server)和远程代理(remote agent)连接处理中存在服务端请求伪造(SSRF)漏洞。攻击者可以通过在注册、更新或测试工具服务器或远程代理时提供精心构造的连接地址,利用该漏洞以经认证的远程用户身份获取应用程序自身容器角色的凭据,并读取来自任意内部网络位置的响应。 为解决此问题,建议用户升级至 1.7.0 或更高版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103956 | 10.0 CRITICAL | Missing authentication for critical function in Loom for AWS |
| CVE-2026-104019 | 9.0 CRITICAL | OS command injection in the Studio Space startup validation script in Amazon SageMaker Dis |
| CVE-2026-103957 | 6.2 MEDIUM | Server-side request forgery in the OAuth2 discovery handling in Loom for AWS |
No comments yet