CNNVD-202511-526 Information
CNNVD ID
CNNVD-202511-526
Related CVE
- CNNVD Published: 2025-11-06
Description (Chinese)
Amazon Web Services Research and Engineering Studio是美国亚马逊(Amazon)公司的一个基于云的研究和工程环境。 Amazon Web Services Research and Engineering Studio 2025.09之前版本存在安全漏洞,该漏洞源于所有权验证问题,可能导致经过身份验证的远程用户查看其他用户的活动桌面会话元数据。
Description (English)
Amazon Web Services Research and Engineering Studio is a cloud-based research and engineering environment for Amazon, United States. The previous version of Amazon Web Services Research and Engineering Studio 2025.09 had a security loophole, which stemmed from the issue of authentication of ownership and could result in remote authentication users viewing other users ’ active desktop session metadata.
Hazard Level
High
Vulnerability Type
其他
Affected Vendor
亚马逊
Published
2025-11-06
Last Modified
2026-02-24
References
https://aws.amazon.com/security/security-bulletins/AWS-2025-026/ https://github.com/aws/res/releases/tag/2025.09 https://github.com/aws/res/security/advisories/GHSA-x3cx-g8g9-75hv
Patch
https://aws.amazon.com/cn/security/security-bulletins/AWS-2025-026/
Share on: