Amazon

Amazon Ssm Agent

2 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.57%
  • Veröffentlicht 28.08.2026 18:02:33
  • Zuletzt bearbeitet 31.08.2026 19:17:15

Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an authenticated remote user whose ssm:SendCommand permission is restricted to the AWS-DownloadContent doc...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 20.04.2022 10:15:08
  • Zuletzt bearbeitet 21.11.2024 06:59:15

Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inject Sudo rules and escalate privileges to root. This occurs in certain situations involving a race condition.