aws-lambda-powertools is vulnerable to Information Disclosure
53
Medium Risk
The DataMasking.erase helper in the data masking utility catches invalid masking expressions and provider errors and returns the original field value instead of failing. An invalid regular expression in the masking configuration or an exception raised by a custom provider's erase implementation triggers this path silently. Applications that treat the result as masked can then write the unmasked sensitive field to a downstream destination such as CloudWatch Logs or S3. The patch raises DataMaskingError on these failures instead of returning the original value.
You are affected if you are using a version that falls within the vulnerable range and you use the data masking utility's erase method with a masking expression or a custom provider that can raise an error.
aws-lambda-powertools is vulnerable to Information Disclosure in versions 3.6.0 - 3.34.0.
Upgrade the aws-lambda-powertools library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.