Insertion of Sensitive Information Into Log File Affecting aws-sam-cli package, versions [,1.122.0)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-AWSSAMCLI-7932045
- published 12 Sep 2024
- disclosed 11 Sep 2024
- credit Unknown
How to fix?
Upgrade aws-sam-cli
to version 1.122.0 or higher.
Overview
aws-sam-cli is an AWS SAM CLI is a CLI tool for local development and testing of Serverless applications
Affected versions of this package are vulnerable to Insertion of Sensitive Information Into Log File through the DockerBuildArgs
parameter, which allows an attacker to view sensitive data in clear text by accessing STDERR
in the AWS SAM CLI output during the sam build
command execution.