In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Improper Encoding or Escaping of Output vulnerabilities in an interactive lesson.
Start learningUpgrade AWSSDK.CloudFront to version 3.7.510.7 or higher.
AWSSDK.CloudFront is an Amazon CloudFront is a content delivery web service. It integrates with other Amazon Web Services products to give developers and businesses an easy way to distribute content to end users with low latency, high data transfer speeds, and no minimum usage commitments.
Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output through the AmazonCloudFrontUrlSigner and AmazonCloudFrontCookieSigner policy document construction code in the CloudFront signers components. An attacker can alter the intended access restrictions in a signed URL or signed cookie policy by supplying resource or IP values containing quotes, backslashes, or control characters. The issue affects applications that pass untrusted input into CloudFront signed URL/cookie generation APIs such as SignUrl, BuildPolicyForSignedUrl, GetCookiesForCannedPolicy, and GetCookiesForCustomPolicy.