CVE Database
/

CVE-2019-10777

Back to search

CVE-2019-10777

Published: Jan 8, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function without any sanitization. It is possible for a user to inject arbitrary commands to the "zipCmd" used within "config.FunctionName".

VendorProductVersions

n/a

aws-lambda

affected
All versions prior to version 1.0.5

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now