以下是该漏洞描述的中文翻译: 在 Amazon 的 的 AWS 安全代理插件中,由于缺少对 S3 存储桶所有权的验证(版本低于 1.1.0),远程攻击者可能通过一个预先注册的存储桶(其名称由公知的账户标识符推导得出)获取被扫描工作区的私有源存档,该存档中包含凭据和基础设施状态等敏感信息。 修复建议: 1. 用户应升级至 1.1.0 版本以修复此问题。 2. 用户还应核实其账户中的扫描输出存储桶是否归其自有账户所有,因为升级新版本不会释放已被第三方预先注册的存储桶名称。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AWS | AWS Security Agent plugin | 1.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet