Amazon Open source MCP servers for AWS是美国Amazon公司的一款亚马逊云服务连接的模块集合。 Amazon Open source MCP servers for AWS 0.1.0版本至0.1.4版本存在路径遍历漏洞,该漏洞源于对get_resource工具中savePath参数的路径限制不当,可能允许依赖上下文的攻击者在预期工作目录之外写入任意文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AWS | aws-transform-mcp-server | 0.1.0≤ 0.1.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AWS | aws-transform-mcp-server | 0.1.0 ~ 0.1.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet