Impact
The failure‑open logic in the data masking utility allows an attacker to read values that were intended to be hidden. This flaw can expose sensitive information in logs or responses, compromising confidentiality. The weakness is a classic fail‑safe coding issue (CWE‑390) where error handling accepts the original data instead of masking it.
Affected Systems
AWS Powertools for Lambda (Python) library before version 3.35.0. The 3.35.0 release resolves the issue, so any application using an earlier release is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6 indicates moderate risk. No exploit probability data is available, and the vulnerability is not listed in the KEV catalog. An attacker could attempt to induce an error in the masking function through crafted input or misconfigured Lambda contexts, but no public exploit has been documented. The attack requires application language access to the payload and the ability to trigger the data masking routine.
OpenCVE Enrichment