Kerentanan  ·  2026-09-11

AWS Security Agent / MCP server — missing S3 bucket ownership check mengekspos scanned-workspace source archives (credentials, infra state)

KerentananMedium dampakGlobalCVE-2026-87912
Dua related AWS-published bulletins mendeskripsikan root cause yang sama — missing S3 bucket-ownership verification — dalam kedua DevSecOps Security Agent plugin dan MCP server counterpart-nya, memungkinkan penyerang yang pre-registers specific bucket name untuk menerima source archive dari setiap workspace yang dipindai oleh vulnerable instance.
AI-driven security-scanning agents sedang diadopsi secara luas untuk automated vulnerability triage; flaw yang silently mengalirkan full source-code archives (termasuk embedded secrets) ke attacker-controlled bucket merusak trust model dari tepat tooling yang dimaksudkan untuk meningkatkan security posture.
Missing S3 bucket-ownership verification check memungkinkan remote attacker untuk pre-register storage bucket yang tool subsequently tulis scanned workspace archives ke, mengekspos private source archive — termasuk setiap embedded credentials dan infrastructure state — dari setiap workspace yang dipindai oleh affected instance.
aws-agents-for-devsecops AWS Security Agent plugin, versi sebelum 1.1.0; AWS Security Agent MCP server, versi sebelum 0.2.0
Upgrade aws-agents-for-devsecops ke 1.1.0+ dan AWS Security Agent MCP server ke 0.2.0+; verifikasi S3 bucket ownership divalidasi sebelum write dalam setiap custom integration. AWS Security Bulletin 2026-105.
AWS Security Bulletin 2026-105NVD - CVE-2026-87912
Lihat di umpan langsung Jelajahi temuan keamanan dan tata kelola AI terkait — diperbarui setiap pagi.
Buka umpan →