Amazon Web Services Research and Engineering Studio是美国亚马逊(Amazon)公司的一个基于云的研究和工程环境。 Amazon Web Services Research and Engineering Studio 2024.10至2025.12.01版本存在安全漏洞,该漏洞源于FileBrowser API输入未清理,可能导致远程认证攻击者通过特制输入在使用FileBrowser功能时在集群管理器EC2实例上执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AWS | Research and Engineering Studio (RES) | 2024.10 ~ 2025.12.01 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-5708 | 8.8 HIGH | Improper Control of User-Modifiable Attributes in RES CreateSession API |
| CVE-2026-5707 | 8.8 HIGH | Command Injection via Virtual Desktop Session Name in AWS Research and Engineering Studio |
No comments yet