CVE-2025-3048

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Mar 31, 2025
Updated: Apr 1, 2025
CWE ID 22
CWE ID 497

Summary

CVE-2025-3048 is a vulnerability affecting the AWS Serverless Application Model Command Line Interface (SAM CLI). When building applications with symlinks, SAM CLI copies the content of these symlinks to the local workspace as regular files or directories. This issue grants unauthorized access to users who don't have access to the symlinks outside of the Docker container. Users are advised to upgrade to version 1.134.0 and apply the necessary patches to forked or derivative code. After upgrading, re-building applications using 'sam build --use-container' is required to update the symlinks and mitigate the vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share