When the AWS Cloud Development Kit (AWS CDK) Command Line Interface (AWS CDK CLI) is used with a credential plugin which returns an expiration property with the retrieved AWS credentials, the credentials are printed to the console output. To mitigate this issue, users should upgrade to version 2.178.2 or later and ensure any forked or derivative code is patched to incorporate the new fixes.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Mar 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 21 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Mar 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When the AWS Cloud Development Kit (AWS CDK) Command Line Interface (AWS CDK CLI) is used with a credential plugin which returns an expiration property with the retrieved AWS credentials, the credentials are printed to the console output. To mitigate this issue, users should upgrade to version 2.178.2 or later and ensure any forked or derivative code is patched to incorporate the new fixes. | |
| Title | AWS CDK CLI prints AWS credentials retrieved by custom credential plugins | |
| Weaknesses | CWE-497 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published: 2025-03-21T14:14:29.040Z
Updated: 2025-03-21T16:27:39.401Z
Reserved: 2025-03-21T11:48:52.961Z
Link: CVE-2025-2598
Updated: 2025-03-21T15:20:52.582Z
Status : Received
Published: 2025-03-21T15:15:43.120
Modified: 2025-03-21T17:15:40.090
Link: CVE-2025-2598
No data.