Intel

AIKIDO-2025-10123

aws-sdk-java is vulnerable to Information Disclosure

Information Disclosure Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 3, 2025

28

Low Risk

This Affects:

javaaws-sdk-java
2.10.21 - 2.30.29
Fixed in 2.30.30
Are you affected? Scan for Free

TL;DR

Affected versions of this package are affected by improper handling of SecurityException when accessing the AWS shared credentials file, potentially allowing privilege escalation. An attacker with restricted permissions can trigger a SecurityException to force the application into an insecure state, exposing sensitive data and bypassing intended security restrictions to access profile files, credentials, and secrets.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

aws-sdk-java is vulnerable to Information Disclosure in versions 2.10.21 - 2.30.29.

How to fix this

Upgrade the software.amazon.awssdk:aws-sdk-java library to the patch version.