漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
Vulnerability Description
Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 might allow man-in-the-middle attackers to intercept SSHsessions and file transfers via network positioning between the client and the EMR cluster endpoint. To remediate this issue, users should upgrade to AWS CLI v1 1.45.28 or later, or AWS CLI v2 2.35.3 or later.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
未进行实体认证的密钥交换
Vulnerability Title
Amazon aws-cli 加密问题漏洞
Vulnerability Description
Amazon aws-cli是美国Amazon公司的一个与云服务交互的命令行工具。 Amazon aws-cli 1.45.28之前版本和AWS CLI v2 2.35.3之前版本存在加密问题漏洞,该漏洞源于EMR SSH helper命令中的密钥交换缺少实体认证,可能导致中间人攻击者通过客户端与EMR集群端点之间的网络定位拦截SSH会话和文件传输。
CVSS Information
N/A
Vulnerability Type
N/A