Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 10 min 131 bronnen 1 kritiek 10 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-105811

MEDIUM · 6.5 CVSS Gepubliceerd: CWE-639

Beschrijving NL

Autorisatieomzeiling via een door de gebruiker gecontroleerde sleutel in het optionele Amazon Q Business Lambda-haakmonster (q-business-lambda-hook https://github.com/aws-solutions-library-samples/qnabot-on-aws/blob/main/source/docs/lambda_hooks/README.md), beschikbaar bij QnABot op AWS-versies 7.0.0 tot en met 7.4.5, kan een geverifieerde externe gebruiker in staat stellen om willekeurige Amazon S3-objecten in het implementerende AWS-account te lezen. Deze voorbeeldoplossing biedt een voorbeeld van een Lambda-haak en vereist afzonderlijke, handmatige implementatie en extra installatie. Het wordt niet automatisch geïmplementeerd met QnABot. Klanten die deze optionele monsterhaak niet hebben geïmplementeerd, worden niet beïnvloed en hoeven geen actie te ondernemen. Om dit probleem op te lossen, moeten getroffen klanten de QnABot op AWS-stack bijwerken naar versie 7.4.6 of hoger en vervolgens de Amazon Q Business Lambda-haakmonsterstack opnieuw plaatsen. Het bijwerken van de QnABot op AWS-stack alleen levert de oplossing niet op.

Origineel (Engels) tonen

Authorization bypass through a user-controlled key in the optional Amazon Q Business Lambda hook sample ( q-business-lambda-hook https://github.com/aws-solutions-library-samples/qnabot-on-aws/blob/main/source/docs/lambda_hooks/README.md ), available with QnABot on AWS versions 7.0.0 through 7.4.5, might allow an authenticated remote user to read arbitrary Amazon S3 objects in the deploying AWS account. This sample solution provides an example Lambda hook and requires separate, manual deployment and additional setup. It is not deployed automatically with QnABot. Customers who have not deployed this optional sample hook are not affected and do not need to take action.

To remediate this issue, affected customers should update the QnABot on AWS stack to version 7.4.6 or later and then redeploy the Amazon Q Business Lambda hook sample stack. Updating the QnABot on AWS stack alone does not deliver the fix.

References