CVE-2025-12829
⚪ Do wiadomości
Nieinicjowane odczyty stosu w Amazon Ion-C mogą ujawniać wrażliwe dane w pamięci.
CVSS
6.2
EPSS
0.1%
Exploit
none
Vendor
Opis źródłowy (NVD)
An uninitialized stack read issue exists in Amazon Ion-C versions <v1.1.4 that may allow a threat actor to craft data and serialize it to Ion text in such a way that sensitive data in memory could be exposed through UTF-8 escape sequences. To mitigate this issue, users should upgrade to version v1.1.4.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.2 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.1% |
| Opublikowano (NVD) | 2025-11-07 18:15:35 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 21:10:00 UTC |
Referencje
- https://aws.amazon.com/security/security-bulletins/AWS-2025-027/ (ff89ba41-3aa1-4d27-914a-91399e9639e5)
- https://github.com/amazon-ion/ion-c/releases/tag/v1.1.4 (ff89ba41-3aa1-4d27-914a-91399e9639e5)
- https://github.com/amazon-ion/ion-c/security/advisories/GHSA-7mgf-6x73-5h7r (ff89ba41-3aa1-4d27-914a-91399e9639e5)