RSS   Vulnerabilities for 'Aws-lambda'   RSS

2020-01-08
 
CVE-2019-10777

CWE-78
 

 
In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function without any sanitization. It is possible for a user to inject arbitrary commands to the "zipCmd" used within "config.FunctionName".

 

 >>> Vendor: Amazon 20 Products
Kindle touch
Kindle for pc
Merchant sdk
Elastic load balancing api tools
Flexible payments service
Ec2 api tools java library
Kindle
Fire os
Amazon key firmware
Amazon music
Payfort
Payfort-php-sdk
Amazon web services freertos
Freertos
Amazon web services software development kit
Freertos\+fat
Audible
Firecracker
Aws-lambda
Aws javascript s3 explorer


Copyright 2020, cxsecurity.com

 

Back to Top