在 AWS Security Agent MCP 服务器 0.2.0 版本之前,由于缺少对 S3 存储桶所有权的验证,远程攻击者可能通过一个名称由公开已知的账户标识符派生的预注册存储桶,获取被扫描工作区的私有源归档文件,其中包含该归档中的凭据和基础设施状态。 为修复此问题,用户应升级至 0.2.0 版本。此外,用户还应核对其账户中的扫描输出存储桶确由自己的账户拥有,因为升级并不会释放第三方已注册的桶名称。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AWS | AWS Security Agent MCP server | 0.1.0 ~ 0.1.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet