First published: Wed Jan 08 2020(Updated: )
In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function without any sanitization. It is possible for a user to inject arbitrary commands to the "zipCmd" used within "config.FunctionName".
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon Aws Lambda | <1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.