在 Amazon SageMaker Python SDK 的 和 装饰器管道组件中,v3.11.0 之前以及 v2.256.0 之前,敏感信息以明文形式存储。这可能导致已认证的远程用户从 SageMaker API 的响应中提取 HMAC 签名密钥,并为精心构造的函数载荷伪造有效的完整性签名,从而在同一 AWS 账户内的其他用户的管道执行上下文中实现代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AWS | sagemaker-python-sdk | 0 ~ 3.11.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet