在 AWS aws-cdk-lib 版本低于 2.267.0 的情况下,资产捆绑输出处理中存在文件访问前的链接解析不当问题。此漏洞可能使上下文相关的攻击者能够导致构建主机上的文件被作为部署资产发布。 为缓解此问题,用户应升级至 2.267.0 或更高版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AWS | aws-cdk-lib | 0 ~ 2.267.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107322 | 7.8 HIGH | OS command injection in Amazon Agent Plugins for AWS databases-on-aws |
| CVE-2026-107332 | 5.5 MEDIUM | Insecure Default File Permissions on Cached Credentials in AWS Toolkit for Visual Studio C |
No comments yet