awscli is vulnerable to Incorrect Permission Assignment for Critical Resource
55
Medium Risk
The AWS CLI writes credential and configuration files while running certain subcommands on Unix-like systems. Commands including aws codeartifact login, aws iam create-virtual-mfa-device, and aws deploy register create these files using the inherited process umask instead of enforcing owner-only permissions. Under a default umask the files are created world-readable (0644), so any other local user on the same host can read the stored credentials. The fix explicitly sets restrictive owner-only permissions when these files are written.
You are affected if you are using a version that falls within the vulnerable range and run the affected subcommands on a Unix-like system with a default umask.
awscli is vulnerable to Incorrect Permission Assignment for Critical Resource in versions 0.16.0 - 1.44.77.
Upgrade the awscli library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant