Source |
GB Hacker |
Identifiant |
8672661 |
Date de publication |
2025-05-07 08:22:36 (vue: 2025-05-07 09:07:24) |
Titre |
AWS Critical AWS Amplify Studio Flaw a permis aux attaquants d'exécuter un code arbitraire Critical AWS Amplify Studio Flaw Allowed Attackers to Execute Arbitrary Code |
Texte |
> Amazon Web Services (AWS) a abordé un défaut de sécurité critique (CVE-2025-4318) dans sa plate-forme AWS Amplify Studio, qui aurait pu permettre aux attaquants authentifiés d'exécuter du code JavaScript malveillant pendant le rendu des composants. La vulnérabilité, divulguée publiquement le 5 mai 2025, affecte le package Amplify-Codegen-UI, un outil de base pour générer du code frontal dans Amplify Studio. Détails de la vulnérabilité Le défaut réside dans […]
>Amazon Web Services (AWS) has addressed a critical security flaw (CVE-2025-4318) in its AWS Amplify Studio platform, which could have allowed authenticated attackers to execute malicious JavaScript code during component rendering. The vulnerability, publicly disclosed on May 5, 2025, affects the amplify-codegen-ui package, a core tool for generating front-end code in Amplify Studio. Vulnerability Details The flaw resides in […]
|
Notes |
★★★
|
Envoyé |
Oui |
Condensat |
2025 4318 >amazon addressed affects allowed amplify arbitrary attackers authenticated aws code codegen component core could critical cve details disclosed during end execute flaw front generating has have its aws javascript malicious may publicly rendering resides security services studio studio platform the amplify tool ui package vulnerability web which |
Tags |
Tool
Vulnerability
|
Stories |
|
Move |
|