ZDI-CAN-23901: ZDI-24-1176: Amazon AWS aws-glue-with-s2s-vpn Uncontrolled Search Path Element Remote Code Execution Vulnerability
Published Aug 23, 2024
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Amazon AWS. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8.
Affected Software
1 affected component
Amazon AWS Glue
Event History
Aug 23, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-23901?
The severity of ZDI-CAN-23901 is rated at 9.8 on the CVSS scale, indicating critical vulnerability.
2
What is the impact of ZDI-CAN-23901?
ZDI-CAN-23901 allows remote attackers to execute arbitrary code on affected installations of Amazon AWS without requiring authentication.
3
How do I fix ZDI-CAN-23901?
To fix ZDI-CAN-23901, update affected installations of Amazon AWS Glue to the latest security patch provided by Amazon.
4
Is authentication required to exploit ZDI-CAN-23901?
No, authentication is not required to exploit the ZDI-CAN-23901 vulnerability.
5
Which software is affected by ZDI-CAN-23901?
ZDI-CAN-23901 affects Amazon AWS Glue installations.