consoleme@1.1.5.dev3 vulnerabilities

A central control plane for AWS permissions and access

Direct Vulnerabilities

Known vulnerabilities in the consoleme package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • C
Improper Neutralization of Special Elements used in a Command ('Command Injection')

consoleme is an A central control plane for AWS permissions and access

Affected versions of this package are vulnerable to Improper Neutralization of Special Elements used in a Command ('Command Injection') via the command process. A specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe's role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation.

Note:

Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected.

How to fix Improper Neutralization of Special Elements used in a Command ('Command Injection')?

Upgrade consoleme to version 1.4.0 or higher.

[,1.4.0)
  • M
Information Exposure

consoleme is an A central control plane for AWS permissions and access

Affected versions of this package are vulnerable to Information Exposure via a Python format string issue leading to the possibility of exfiltration of AWS credentials.

How to fix Information Exposure?

Upgrade consoleme to version 1.2.2 or higher.

[,1.2.2)