Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
8.8
CVE-2026-81849
- EPSS 0.57%
- Veröffentlicht 28.08.2026 18:02:33
- Zuletzt bearbeitet 31.08.2026 19:17:15
Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an authenticated remote user whose ssm:SendCommand permission is restricted to the AWS-DownloadContent doc...
- EPSS 0.3%
- Veröffentlicht 20.04.2022 10:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:15
Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inject Sudo rules and escalate privileges to root. This occurs in certain situations involving a race condition.
1