Impact
Loom for AWS is vulnerable to a server‑side request forgery that is triggered when a user supplies a crafted connection address during the registration, update, or test of a tool server or remote agent. Since the request is executed from the Loom container, an authenticated remote user can obtain the credentials tied to the container’s IAM role and can read responses from any internal network endpoint addressed by the crafted URL. This gives the attacker the ability to harvest AWS credentials that grant access to resources in the same account and to exfiltrate data from the internal network, potentially leading to account compromise and data leakage.
Affected Systems
Amazon Web Services’ Loom product (AWS:loom) running any version earlier than 1.7.0 is affected. The vulnerability is present in the tool server and remote agent connection handling modules. No other vended products or services are listed as affected.
Risk and Exploitability
The vulnerability has a CVSS score of 8.3, indicating high impact. Because the EPSS score is not provided, the current exploitation probability is unknown, but the absence of a KEV listing suggests no public exploits are documented yet. Exploitation requires an authenticated user within Loom, but once authenticated the attacker can target arbitrary internal addresses without additional permissions. The attack can be performed without elevating privileges beyond the scope of the Loom service role, making it a significant risk for environments where Loom is exposed to external users.
OpenCVE Enrichment