这是一段关于 Amazon AWS Systems Manager (SSM) Agent 中服务器端请求伪造(SSRF)漏洞的官方描述。以下是该段落的中文翻译: 由于在 Amazon AWS Systems Manager Agent (SSM Agent) 的“端口转发至远程主机”功能中,对等效地址表示(equivalent address representations)的验证不当,导致服务器端请求伪造问题。在版本 3.3.4851.0 之前的所有平台上的 SSM Agent 可能存在此缺陷。 该漏洞允许经过
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AWS | Amazon SSM Agent | < 3.3.4851.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AWS | Amazon SSM Agent | 0 ~ 3.3.4851.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87913 | 5.9 MEDIUM | Missing S3 bucket ownership verification in the AWS Security Agent MCP server |
| CVE-2026-87912 | 5.9 MEDIUM | Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-f |
No comments yet