AWS Amplify Studio Package Input Validation Issue: Early Warning
An input validation issue in AWS Amplify Studio package <=2.20.2 could allow an authenticated user to run arbitrary JavaScript code during component rendering and build process.
What happened
An early warning has been issued regarding a critical vulnerability in the AWS Amplify Studio package. The issue, tracked as GHSA-HF3J-86P7-MFW8, reportedly allows an authenticated user to execute arbitrary JavaScript code during the component rendering and build process. This vulnerability affects versions <=2.20.2 of the @aws-amplify/codegen-ui-react package. It is under investigation and has been classified as a critical CVE. Users are advised to upgrade to version 2.20.4 to mitigate potential risks.
The vulnerability stems from insufficient input validation within the UI component properties. This could potentially be exploited by an authenticated user to inject and execute malicious JavaScript code. The impact of this vulnerability is significant, as it could lead to unauthorized actions within the application. Software engineers using AWS Amplify Studio should assess their exposure by checking if their projects include the affected package versions.
For those affected, the recommended action is to upgrade to version 2.20.4 of @aws-amplify/codegen-ui-react. This update is intended to address the input validation issue and prevent potential exploitation. Further details and updates should be obtained from the primary sources, as the situation is still under investigation.
How 0Day mitigates this
@aws-amplify/codegen-ui-react is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.