aws-cdk is vulnerable to Log injection
20
Low Risk
Affected versions of this package allow attackers to forge log entries or inject malicious content into log files.
You are affected by this flaw if you use a version >= 2.109.0 and = 2.129.0 of this package.
aws-cdk is vulnerable to Log injection in versions 2.109.0 - 2.129.0.
To fix, upgrade to aws-cdk 2.130.0 or above.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant