AWS Kiro의 취약점으로 원격 코드 실행이 가능해짐.
AWS Kiro에서 숨겨진 텍스트로 인해 개발자의 머신에서 공격자의 코드를 실행할 수 있는 취약점이 발견됐다. 연구진은 Kiro에 페이지 요약 요청을 보내는 것만으로도 원격 코드 실행이 가능하다고 밝혔다. 현재 AWS는 이 문제를 패치했으나 CVE는 발행되지 않았다.
A vulnerability in AWS Kiro enabled remote code execution.
A hidden text vulnerability in AWS's Kiro IDE allowed attackers to execute code on a developer's machine without approval. Researchers found that a simple request for Kiro to summarize a page could lead to remote code execution. AWS has issued a patch for this issue, although no CVE has been published.