Amazon AWS Glue Database Password...

- AV AC AU C I A
发布: 2024-04-15
修订: 2024-04-28

The password of database connections in AWS Glue is loaded into the website when a connection's edit page is requested. Principals with appropriate permissions can read the password. This behavior also increases the risk that database passwords will be intercepted by an attacker during transmission in the server response. Many types of vulnerabilities, such as broken access controls, cross site scripting and weaknesses in session handling, could enable an attacker to leverage this behavior to retrieve the passwords.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息