Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Amazon — Vulnerabilities & Security Advisories 54

Browse all 54 CVE security advisories affecting Amazon. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Amazon operates primarily as a global e-commerce platform and cloud computing provider, offering extensive infrastructure services alongside retail operations. With thirty-six recorded Common Vulnerabilities and Exposures, the entity has historically faced risks associated with remote code execution, cross-site scripting, and privilege escalation, reflecting the complexity of its distributed architecture. Security assessments indicate that while the core infrastructure maintains robust controls, peripheral services and third-party integrations often present attack vectors. Notable incidents have included data exposure events and service disruptions, prompting continuous hardening of access controls and encryption standards. The organization’s scale necessitates rigorous monitoring, yet the sheer volume of endpoints and APIs creates a broad attack surface. Analysts observe that while critical backend systems remain resilient, user-facing applications and legacy components occasionally exhibit configuration weaknesses, requiring persistent patch management and vulnerability scanning to mitigate potential exploitation by threat actors targeting sensitive customer data and operational continuity.

CVE ID Title CVSS Severity Published
CVE-2025-8904 Privilege escalation issue in Amazon EMR Secret Agent component — EMR CWE-257 8.5 High 2025-08-13
CVE-2025-8217 Inert Malicious script injected into Amazon Q Developer Visual Studio Code (VS Code) Extension — Q Developer VS Code Extension CWE-506 4.0 Medium 2025-07-30
CVE-2025-6031 Insecure device pairing in end of life Amazon Cloud Cam — Cloud Cam CWE-672 7.5 High 2025-06-12
CVE-2025-5688 Out of Bounds Write in FreeRTOS-Plus-TCP — FreeRTOS CWE-787 9.8AI Critical AI 2025-06-04
CVE-2025-5279 Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin — Redshift CWE-295 7.5AI High AI 2025-05-27
CVE-2025-4318 Input validation issue in AWS Amplify Studio UI component properties — Amplify Studio CWE-95 9.0 Critical 2025-05-05
CVE-2025-3857 Infinite loop condition in Amazon.IonDotnet — Amazon Ion Dotnet CWE-835 7.5 High 2025-04-21
CVE-2025-0501 Issue affecting Amazon WorkSpaces Clients (when running PCoIP protocol) — WorkSpaces Client CWE-295 7.5 High 2025-01-15
CVE-2025-0500 Issue affecting Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV clients — WorkSpaces Client CWE-295 7.5 High 2025-01-15
CVE-2024-12746 SQL Injection in the Amazon Redshift ODBC Driver affecting v2.1.5.0 — Amazon Redshift ODBC Driver CWE-89 8.0 High 2024-12-24
CVE-2024-12745 SQL Injection in the Amazon Redshift Python Connector affecting v2.1.4 — Amazon Redshift Python Connector CWE-89 8.0 High 2024-12-24
CVE-2024-12744 SQL Injection in the Amazon Redshift JDBC Driver affecting v2.1.0.31 — Amazon Redshift JDBC Driver CWE-89 8.0 High 2024-12-24
CVE-2024-52314 data.all admin user may access potentially sensitive data stored by producers via logs — data.all CWE-863 4.9 Medium 2024-11-09
CVE-2024-52312 data.all authenticated users can perform restricted operations against DataSets and Environments — data.all CWE-863 5.4 Medium 2024-11-09
CVE-2024-52313 data.all authenticated users can obtain incorrect object level authorizations — data.all CWE-639 4.3 Medium 2024-11-09
CVE-2024-10953 data.all authenticated users can perform mutating update operations on persisted notification records — data.all CWE-863 4.3 Medium 2024-11-09
CVE-2024-52311 data.all does not invalidate authentication token upon user logout — data.all CWE-613 6.3 Medium 2024-11-09
CVE-2024-10125 Lack of JWT issuer and signer validation — Amazon.ApplicationLoadBalancer.Identity.AspNetCore Middleware CWE-290 7.5 High 2024-10-21
CVE-2024-8901 Lack of JWT issuer and signer validation — AWS ALB Route Directive Adapter For Istio CWE-290 7.5 High 2024-10-21
CVE-2023-1385 Amazon Fire TV Stick 安全特征问题漏洞 — Fire TV Stick 3rd gen CWE-330 7.1 High 2023-05-03
CVE-2023-1384 Amazon Fire TV Stick 跨站脚本漏洞 — Fire TV Stick 3rd gen CWE-80 4.3 Medium 2023-05-03
CVE-2020-8897 Robustness weakness in AWS KMS and Encryption SDKs — AWS SDK CWE-310 4.8 Medium 2020-11-16
CVE-2019-3984 Blink XT2 Sync Module 操作系统命令注入漏洞 — Blink XT2 Sync Module firmware 9.8 - 2019-12-31
CVE-2018-1169 Amazon Music Player 安全漏洞 — Amazon Music Player CWE-78 8.8 - 2018-03-02

This page lists every published CVE security advisory associated with Amazon. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.