Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths
Vulnerability Description
Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions that cause writes to execution-sensitive paths (such as .vscode/tasks.json), enabling auto-execution on folder open. To remediate this issue, users should upgrade to Kiro IDE version 0.11 or later.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
关键资源的不正确权限授予
Vulnerability Title
Amazon Kiro IDE 安全漏洞
Vulnerability Description
Amazon Kiro IDE是美国亚马逊(Amazon)公司的一款基于AI规格驱动开发的集成开发环境。 Amazon Kiro IDE 0.11之前版本存在安全漏洞,该漏洞源于文件写入工具中访问控制限制不足,可能导致远程未认证攻击者通过特制指令写入执行敏感路径,在文件夹打开时自动执行。
CVSS Information
N/A
Vulnerability Type
N/A