AWS SDK XML Parser XpathUtils.java XpathUtils server-side request forgery
Published Dec 24, 2022
9.8
CRITICALCVSS 3.1
EPSS 0.70%
Description
A vulnerability was found in AWS SDK 2.59.0. It has been rated as critical. This issue affects the function XpathUtils of the file aws-android-sdk-core/src/main/java/com/amazonaws/util/XpathUtils.java of the component XML Parser. The manipulation leads to server-side request forgery. Upgrading to version 2.59.1 is able to address this issue. The name of the patch is c3e6d69422e1f0c80fe53f2d757b8df97619af2b. It is recommended to upgrade the affected component. The identifier VDB-216737 was assigned to this vulnerability.
Affected products
- Vendor n/a Product AWS Sdk Defaultn/a
- Version 2.59.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | AWS Sdk | n/a |
|
- < 2.59.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://github.com/advisories/GHSA-f5h9-qx38-2hgp Advisory
- https://github.com/aws-amplify/aws-sdk-android/commit/c3e6d69422e1f0c80fe53f2d757b8df97619af2b mitigationpatchThird Party Advisory
- https://github.com/aws-amplify/aws-sdk-android/pull/3100 relatedPatchThird Party Advisory
- https://github.com/aws-amplify/aws-sdk-android/releases/tag/release_v2.59.1 mitigationRelease NotesThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-4725
- https://vuldb.com/?id.216737 technical-descriptionvdb-entryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-f5h9-qx38-2hgp | Advisory | |
| https://github.com/aws-amplify/aws-sdk-android/commit/c3e6d69422e1f0c80fe53f2d757b8df97619af2b | mitigationpatchThird Party Advisory | |
| https://github.com/aws-amplify/aws-sdk-android/pull/3100 | relatedPatchThird Party Advisory | |
| https://github.com/aws-amplify/aws-sdk-android/releases/tag/release_v2.59.1 | mitigationRelease NotesThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-4725 | ||
| https://vuldb.com/?id.216737 | technical-descriptionvdb-entryThird Party Advisory |
Change history (0)
No recorded changes yet.