aws-solutions/qnabot-on-aws

Critical Vulnerabilities in aws inspector

Closed this issue · 6 comments

Hi @abhirpat,

Last week in AWS inspector critical vulnerabilities has been identified in multiple lambdas. We ran the v6.0.1 version of cloudformation. Could you please help in this.
image
CVE-2024-7042 - @langchain/community, langchain
image
CVE-2024-7774 - langchain
image

Hi @anjugds ,
thanks for reporting this with detailed information. We will look into this and revert back.

Hi @abhirpat

We ran the v6.1.3 version of cloudformation and this is a critical vulnerability in our account. Could you please help us with this?

hi @fhoueto-amz , We are currently awaiting a resolution, as this issue is impacting a client project and is preventing further production deployments. Your prompt assistance is needed, as this involves a critical vulnerability with prompt injection and SQL injection.

Hi @anjugds, we are planning to address this in the next CVE patch release (6.1.5) sometime this week. Thanks again for bringing this up!

Were you able to deploy the CVE Patch yesterday?

@mfarnga v6.1.5 CVE Patch is out, see.

Closing this ticket.