Intel

AIKIDO-2024-10004

aws-cdk is vulnerable to Log injection

Log injection Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 26, 2024

20

Low Risk

This Affects:

pythonaws-cdk
2.109.0 - 2.129.0
Fixed in 2.130.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package allow attackers to forge log entries or inject malicious content into log files.

Who does this affect?

You are affected by this flaw if you use a version >= 2.109.0 and = 2.129.0 of this package.

Background info

aws-cdk is vulnerable to Log injection in versions 2.109.0 - 2.129.0.

How to fix this

To fix, upgrade to aws-cdk 2.130.0 or above.