ã¯ããã« ããã«ã¡ã¯ãæ ªå¼ä¼ç¤¾Flatt Security ã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã®æ£®å²¡(@scgajge12)ã§ãã æ¬ç¨¿ã§ã¯ãAWS Lambda ã§èµ·ããããèå¼±æ§æ»æããªã¹ã¯ãã»ãã¥ãªãã£å¯¾çã解説ãããµã¼ãã¼ã¬ã¹ã«ãããã»ãã¥ãªãã£ãªã¹ã¯ã«ã¤ãã¦ç´¹ä»ãã¾ãã ã¯ããã« AWS Lambda ã«ã¤ã㦠ãµã¼ãã¼ã¬ã¹ã«ãããã»ãã¥ãªãã£ãªã¹ã¯ AWS Lambda ã§èµ·ããããèå¼±æ§æ»æ Lambda ã§ã®èå¼±æ§æ»æã«ãããªã¹ã¯ èå¼±æ§æ»æã«ããæ´ãªããªã¹ã¯ OS Command Injection XML External Entity (XXE) Insecure Deserialization Server Side Request Forgery (SSRF) Remote Code Execution (RCE) AWS Lambda ã«ãããã»ãã¥ãªãã£å¯¾ç ã»ãã¥ãªãã£
ã©ã³ãã³ã°
ãç¥ãã
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}