Amazon · Amazon Workspaces Client For Linux · CVE-2025-12779
**Name of the Vulnerable Software and Affected Versions**
Amazon WorkSpaces client for Linux versions 2023.0 through 2024.8
**Description**
A flaw in the handling of the authentication token within the Amazon WorkSpaces client for Linux may allow exposure of the authentication token for DCV-based WorkSpaces to other local users on the same client machine. A local user may be able to extract another local user's authentication token and access their WorkSpace under certain circumstances.
**Recommendations**
Upgrade to Amazon WorkSpaces client for Linux version 2025.0 or later.