PT-2024-40458 · Amazon Web Services · Aws Sam Cli

Published

2024-09-11

·

Updated

2024-09-11

CVSS v4.0

5.7

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions AWS SAM CLI versions prior to 1.122.0
Description The issue concerns the exposure of sensitive data in the AWS SAM CLI output via STDERR when running the sam build command. If customers specify sensitive data in the DockerBuildArgs parameter of their template, this data will be shown in clear text.
Recommendations For versions prior to 1.122.0, update to AWS SAM CLI version 1.122.0 or above to resolve the issue. Additionally, review logs produced by SAM CLI runs if the DockerBuildArgs parameter was used and consider rotating secrets if exposure is suspected.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-RJC6-VM4H-85CG

Affected Products

Aws Sam Cli