aws-sdk-java is vulnerable to Information Disclosure
28
Low Risk
Affected versions of this package are affected by improper handling of SecurityException when accessing the AWS shared credentials file, potentially allowing privilege escalation. An attacker with restricted permissions can trigger a SecurityException to force the application into an insecure state, exposing sensitive data and bypassing intended security restrictions to access profile files, credentials, and secrets.
You are affected if you are using a version that falls within the vulnerable range.
aws-sdk-java is vulnerable to Information Disclosure in versions 2.10.21 - 2.30.29.
Upgrade the software.amazon.awssdk:aws-sdk-java library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant