Amazon Agent 插件(针对 aws/databases-on-aws 插件)在 1.7.1 版本之前存在一个被禁止输入列表不完整的问题,这可能允许远程未认证的攻击者通过向代理上下文中引入特制的数据库命令值,在运行该辅助程序的宿主机上执行任意操作系统命令。 为解决此问题,用户应升级到 databases-on-aws 插件的 1.7.1 或更高版本,并验证该已更新的插件在其使用的各个环境中处于激活状态。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| aws | databases-on-aws | < 1.7.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| aws | databases-on-aws | 0 ~ 1.7.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107332 | 5.5 MEDIUM | Insecure Default File Permissions on Cached Credentials in AWS Toolkit for Visual Studio C |
| CVE-2026-107608 | 5.5 MEDIUM | Improper link resolution in asset bundling output handling in aws-cdk-lib |
No comments yet