QID 983790
QID 983790: Nodejs (npm) Security Update for aws-lambda (GHSA-934x-72xh-5hrg)
In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function without any sanitization. It is possible for a user to inject arbitrary commands to the "zipCmd" used within "config.FunctionName".
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-934x-72xh-5hrg for updates pertaining to this vulnerability.
Vendor References
- GHSA-934x-72xh-5hrg -
github.com/advisories/GHSA-934x-72xh-5hrg
CVEs related to QID 983790
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-934x-72xh-5hrg | aws-lambda |
|