CVE-2025-2598
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Mar 21, 2025
CWE ID 497
Summary
CVE-2025-2598 is a vulnerability affecting the AWS Cloud Development Kit (AWS CDK) Command Line Interface (CLI). When using a credential plugin that returns an expiration property, the AWS credentials are inadvertently printed to the console output. This issue poses a security risk, as sensitive AWS credentials may be exposed. To address this vulnerability, users are advised to upgrade to AWS CDK CLI version 2.178.2 or later. Additionally, any forked or derivative code must be patched to incorporate the necessary fixes.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Amazon Web Services