CNNVD-202511-526 Information

CNNVD ID

CNNVD-202511-526

CVE-2025-12815

  • CNNVD Published: 2025-11-06

Description (Chinese)

Amazon Web Services Research and Engineering Studio是美国亚马逊(Amazon)公司的一个基于云的研究和工程环境。 Amazon Web Services Research and Engineering Studio 2025.09之前版本存在安全漏洞,该漏洞源于所有权验证问题,可能导致经过身份验证的远程用户查看其他用户的活动桌面会话元数据。

Description (English)

Amazon Web Services Research and Engineering Studio is a cloud-based research and engineering environment for Amazon, United States. The previous version of Amazon Web Services Research and Engineering Studio 2025.09 had a security loophole, which stemmed from the issue of authentication of ownership and could result in remote authentication users viewing other users ’ active desktop session metadata.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

亚马逊

Published

2025-11-06

Last Modified

2026-02-24

References

https://aws.amazon.com/security/security-bulletins/AWS-2025-026/ https://github.com/aws/res/releases/tag/2025.09 https://github.com/aws/res/security/advisories/GHSA-x3cx-g8g9-75hv

Patch

https://aws.amazon.com/cn/security/security-bulletins/AWS-2025-026/

Share on: