AWS CloudShell Terminal Escape Injection / Remote Code Execution
Posted by deepcore on May 11, 2021 – 2:01 am
The javascript terminal emulator used by AWS CloudShell handles certain terminal escape codes incorrectly. This can lead to remote code execution if attacker controlled data is displayed in a CloudShell instance.
Post a reply
You must be logged in to post a comment.