Impact
A missing verification step in the AWS Security Agent plugin allows a remote attacker to retrieve the private source archive of a scanned workspace. The archive can contain credentials and full infrastructure state, leading to a confidentiality breach of user data. The flaw is tied to CWE-283 (Improper Authorization) and CWE-341 (Weak Random Number Generation).
Affected Systems
All installations of the AWS Security Agent plugin earlier than version 1.1.0 are vulnerable. The vulnerability exists in the aws-agents-for-devsecops toolchain where the S3 bucket name is derived not validated.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium impact severity. EPSS data is not available and the issue is not listed in the CISA KEV catalog. The attack vector requires the attacker to know the account identifier and the pre-registered bucket name; once the target’s bucket is not under the user’s ownership the attacker can download the archive. No public exploitation reports are documented, so the immediate risk is moderate but mitigatable with configuration or software updates.
OpenCVE Enrichment