在 devopspolis secrets-replicator(最高至 0.4.0 版本)中发现了一个漏洞。受影响的组件是 AssumeRole Handler,具体位于 src/handler.py 文件中的 process_single_secret 函数。该漏洞源于对参数 external_id 的错误处理,导致权限分配不正确。攻击者可远程利用此漏洞。建议升级到 0.5.0 版本以解决此问题。该漏洞的修复补丁为 b42239405fbf4fae3c3f0048fc0b4225112edceb。建议尽快升级受
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| devopspolis | secrets-replicator | 0.1 |
cpe:2.3:a:devopspolis:secrets-replicator:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet