Apa yang terjadi
Dua related AWS-published bulletins mendeskripsikan root cause yang sama — missing S3 bucket-ownership verification — dalam kedua DevSecOps Security Agent plugin dan MCP server counterpart-nya, memungkinkan penyerang yang pre-registers specific bucket name untuk menerima source archive dari setiap workspace yang dipindai oleh vulnerable instance.
Mengapa penting
AI-driven security-scanning agents sedang diadopsi secara luas untuk automated vulnerability triage; flaw yang silently mengalirkan full source-code archives (termasuk embedded secrets) ke attacker-controlled bucket merusak trust model dari tepat tooling yang dimaksudkan untuk meningkatkan security posture.
Vektor serangan
Missing S3 bucket-ownership verification check memungkinkan remote attacker untuk pre-register storage bucket yang tool subsequently tulis scanned workspace archives ke, mengekspos private source archive — termasuk setiap embedded credentials dan infrastructure state — dari setiap workspace yang dipindai oleh affected instance.
Sistem yang terdampak
aws-agents-for-devsecops AWS Security Agent plugin, versi sebelum 1.1.0; AWS Security Agent MCP server, versi sebelum 0.2.0
Mitigasi
Upgrade aws-agents-for-devsecops ke 1.1.0+ dan AWS Security Agent MCP server ke 0.2.0+; verifikasi S3 bucket ownership divalidasi sebelum write dalam setiap custom integration. AWS Security Bulletin 2026-105.