Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

aws — Vulnerabilities & Security Advisories 119

Browse all 119 CVE security advisories affecting aws. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Amazon Web Services operates as a comprehensive cloud computing platform, providing infrastructure, storage, and networking solutions to enterprises globally. With 68 recorded Common Vulnerabilities and Exposures, the platform’s security landscape reflects the complexity of its vast ecosystem. Historically, identified flaws have predominantly involved cross-site scripting, remote code execution, and privilege escalation issues, often stemming from misconfigurations or third-party component dependencies rather than core hypervisor failures. Notable incidents have occasionally highlighted risks associated with shared responsibility models, where customer-side errors led to data exposure. Despite these challenges, AWS maintains robust isolation mechanisms and continuous monitoring protocols. The frequency of vulnerabilities underscores the necessity for rigorous patch management and strict access controls. Users must remain vigilant, recognizing that while the underlying infrastructure is hardened, the security of deployed workloads largely depends on proper configuration and adherence to best practices within the shared responsibility framework.

CVE ID Title CVSS Severity Published
CVE-2025-12967 Npgsql 安全漏洞 — JDBC Wrapper CWE-470 8.0 High 2025-11-10
CVE-2025-12815 Amazon Web Services Research and Engineering Studio 安全漏洞 — Research and Engineering Studio (RES) CWE-283 4.3 Medium 2025-11-06
CVE-2025-11618 Invalid Pointer Dereference when receiving UDP/IPv6 packets in FreeRTOS-Plus-TCP — FreeRTOS-Plus-TCP CWE-476 4.3 Medium 2025-10-10
CVE-2025-11617 Buffer Over-read when receiving IPv6 packets with incorrect payload length in FreeRTOS-Plus-TCP — FreeRTOS-Plus-TCP CWE-126 5.4 Medium 2025-10-10
CVE-2025-11616 Buffer Over-read when receiving improperly sized ICMPv6 packets in FreeRTOS-Plus-TCP — FreeRTOS-Plus_TCP CWE-126 5.4 Medium 2025-10-10
CVE-2025-11462 Local Privilege Escalation Vulnerability in AWS Client VPN macOS Client — Client VPN CWE-59 7.8 High 2025-10-07
CVE-2025-8069 Local Privilege Escalation Vulnerability in AWS Client VPN Windows Client — Client VPN CWE-276 7.8 High 2025-07-23
CVE-2025-3048 Path Traversal in AWS SAM CLI allows file copy to local cache — AWS Serverless Application Model Command Line Interface CWE-61 6.5 Medium 2025-03-31
CVE-2025-3047 Path Traversal in AWS SAM CLI allows file copy to build container — AWS Serverless Application Model Command Line Interface CWE-61 6.5 Medium 2025-03-31
CVE-2025-2888 Improper timestamp caching during snapshot rollback in tough — tough CWE-1025 3.7AI Low AI 2025-03-27
CVE-2025-2887 Failure to detect delegated target rollback in tough — tough CWE-1025 5.3AI Medium AI 2025-03-27
CVE-2025-2886 Terminating targets role delegations are not respected in tough — tough CWE-670 4.3AI Medium AI 2025-03-27
CVE-2025-2885 Root metadata version not validated in tough — tough CWE-1288 6.5AI Medium AI 2025-03-27
CVE-2025-2598 AWS CDK CLI prints AWS credentials retrieved by custom credential plugins — Cloud Development Kit Command Line Interface CWE-497 5.5 Medium 2025-03-21
CVE-2025-0508 MD5 Hash Collision in SageMaker Workflow in aws/sagemaker-python-sdk — aws/sagemaker-python-sdk CWE-328 7.5 - 2025-03-20
CVE-2025-1969 Request approval spoofing in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center — Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center CWE-807 4.3 Medium 2025-03-04
CVE-2025-0851 Path traversal issue in Deep Java Library — DeepJavaLibrary CWE-36 9.8 Critical 2025-01-29
CVE-2025-0693 Issue with AWS Sign-in IAM User Login Flow - Possible Username Enumeration — AWS Sign-in IAM Login Flow CWE-204 5.3 Medium 2025-01-23
CVE-2025-23206 IAM OIDC custom resource allows connection to unauthorized OIDC provider in aws-cdk — aws-cdk CWE-347 8.1 - 2025-01-17
CVE-2024-45037 AWS CDK RestApi not generating authorizationScope correctly in resultant CFN template — aws-cdk CWE-863 6.4 Medium 2024-08-27
CVE-2024-32888 Amazon JDBC Driver for Redshift SQL Injection via line comment generation — amazon-redshift-jdbc-driver CWE-89 10.0 Critical 2024-05-15
CVE-2024-34072 Deserialization of Untrusted Data in sagemaker-python-sdk — sagemaker-python-sdk CWE-502 7.8 High 2024-05-03
CVE-2024-34073 Command Injection in sagemaker-python-sdk — sagemaker-python-sdk CWE-78 7.8 High 2024-05-03
CVE-2023-51651 Potential URI resolution path traversal in the AWS SDK for PHP — aws-sdk-php CWE-22 6.0 Medium 2023-12-22
CVE-2023-35165 AWS CDK EKS overly permissive trust policies — aws-cdk CWE-863 6.6 Medium 2023-06-23
CVE-2022-46174 Race condition during concurrent TLS mounts in efs-utils — efs-utils CWE-362 4.2 Medium 2022-12-28
CVE-2022-23511 Amazon CloudWatch Agent 安全漏洞 — amazon-cloudwatch-agent CWE-274 7.1 High 2022-12-12
CVE-2022-31159 Partial Path Traversal in com.amazonaws:aws-java-sdk-s3 — aws-sdk-java CWE-22 7.9 High 2022-07-15
CVE-2022-24709 Cross site scripting in @awsui/components-react — awsui-documentation CWE-79 8.8 High 2022-02-24

This page lists every published CVE security advisory associated with aws. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.