Improper authentication token handling in the Amazon WorkSpaces client for Linux
aws.amazon.com·1d
Flag this post

Bulletin ID: AWS-2025-025** Scope: AWS Content Type:** Important (requires attention) Publication Date: 2025/11/5 1:20 PM PDT

Description:

We identified CVE-2025-12779, which describes an issue in the Amazon WorkSpaces client for Linux . Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8, may expose the authentication token for DCV-based WorkSpaces to other local users on the same client machine. Under certain circumstances, an unintended user may be able to extract a valid authentication token from the client machine and access another user’s WorkSpace. We have proactively communicated with customers regarding the end of support for the impacted …

Similar Posts

Loading similar posts...