在 projen 0.103.0 之前的版本中,任务合成组件中对操作系统命令中使用的特殊元素(如 shell 元字符)未进行适当中和。这可能允许具有上下文的攻击者通过项目配置值或仓库文件名中的 shell 元字符,将其插入到生成的任务定义中,从而在开发者工作站或持续集成(CI)运行器上执行任意命令。 要修复此问题,用户应升级到版本 0.103.0,并重新合成项目,以便使用修正后的任务定义重新生成 文件。仅升级版本并不足够,因为生成的任务定义文件已被提交到仓库中,必须重新生成以应用修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89065 | 7.1 HIGH | Relative path traversal in the generated file manifest cleanup component in projen |
| CVE-2026-18061 | 5.9 MEDIUM | Improper Restriction of XML External Entity References in AWS Advanced JDBC Wrapper Remote |
| CVE-2026-89090 | 5.9 MEDIUM | Denial of service in the event stream header decoder in AWS SDK for Go v2 |
No comments yet