aws-cdk-lib@2.182.0 vulnerabilities

Version 2 of the AWS Cloud Development Kit library

  • latest version

    2.188.0

  • latest non vulnerable version

  • first published

    4 years ago

  • latest version published

    3 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the aws-cdk-lib package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Insertion of Sensitive Information into Log File

    aws-cdk-lib is a Version 2 of the AWS Cloud Development Kit library

    Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File via the DescribeCognitoUserPoolClient CDK API. A user with access to the account where logs for this user pool are stored, and read permissions on the associated lambda function logs, can see the secrets generated by other users' cognito.UserPoolClient constructs.

    Note: After upgrading, applications must be redeployed with the feature flag @aws-cdk/cognito:logUserPoolClientSecretValue set to false to remediate this vulnerability.

    How to fix Insertion of Sensitive Information into Log File?

    Upgrade aws-cdk-lib to version 2.187.0 or higher.

    >=2.37.0 <2.187.0
    • M
    Incorrect Default Permissions

    aws-cdk-lib is a Version 2 of the AWS Cloud Development Kit library

    Affected versions of this package are vulnerable to Incorrect Default Permissions in the IAM trust policy. A user with sts:AssumeRole permissions can escalate privileges to those defined by the IAM trust policy, including performing unauthorized actions on CloudFormation, CodeCommit, Lambda, and ECS.

    Note: After upgrading to the patched version, the feature flag @aws-cdk/pipelines:reduceStageRoleTrustScope must be set to true, and applications redeployed.

    How to fix Incorrect Default Permissions?

    Upgrade aws-cdk-lib to version 2.184.0 or higher.

    <2.184.0