When the AWS Cloud Development Kit (AWS CDK) Command Line Interface (AWS CDK CLI) is used with a credential plugin which returns an expiration property with the retrieved AWS credentials, the credentials are printed to the console output. To mitigate this issue, users should upgrade to version 2.178.2 or later and ensure any forked or derivative code is patched to incorporate the new fixes.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Mar 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Fri, 21 Mar 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 21 Mar 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | When the AWS Cloud Development Kit (AWS CDK) Command Line Interface (AWS CDK CLI) is used with a credential plugin which returns an expiration property with the retrieved AWS credentials, the credentials are printed to the console output. To mitigate this issue, users should upgrade to version 2.178.2 or later and ensure any forked or derivative code is patched to incorporate the new fixes. | |
Title | AWS CDK CLI prints AWS credentials retrieved by custom credential plugins | |
Weaknesses | CWE-497 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2025-03-21T16:27:39.401Z
Reserved: 2025-03-21T11:48:52.961Z
Link: CVE-2025-2598

Updated: 2025-03-21T15:20:52.582Z

Status : Received
Published: 2025-03-21T15:15:43.120
Modified: 2025-03-21T17:15:40.090
Link: CVE-2025-2598

No data.