CVE-2026-104002
⚪ Do wiadomości
Błąd obsługi w Powertools dla AWS Lambda umożliwia odczyt wrażliwych danych zamiast ich maskowania.
CVSS
5.3
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)
A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask. To remediate this issue, users should upgrade to version 3.35.0.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2026-10-01 22:17:00 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-02 19:16:40 UTC |
Referencje
- https://aws.amazon.com/security/security-bulletins/2026-123-aws/ (ff89ba41-3aa1-4d27-914a-91399e9639e5)
- https://github.com/aws-powertools/powertools-lambda-python/releases/tag/v3.35.0 (ff89ba41-3aa1-4d27-914a-91399e9639e5)
- https://github.com/aws-powertools/powertools-lambda-python/security/advisories/GHSA-3vxg-4xv2-jfh5 (ff89ba41-3aa1-4d27-914a-91399e9639e5)