Insecure permissions in autodeploy-layer v1.2.0 allows attackers to escalate privileges and compromise the customer cloud account.
References
Link | Resource |
---|---|
https://gist.github.com/zolaer9527/9a703e9dc575bf1889b275caf7121578 | Third Party Advisory |
Configurations
History
14 Oct 2025, 20:22
Type | Values Removed | Values Added |
---|---|---|
References | () https://gist.github.com/zolaer9527/9a703e9dc575bf1889b275caf7121578 - Third Party Advisory | |
CPE | cpe:2.3:a:lumigo:autodeploy-layer:*:*:*:*:*:*:*:* | |
First Time |
Lumigo
Lumigo autodeploy-layer |
23 May 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-22 17:15
Updated : 2025-10-14 20:22
NVD link : CVE-2025-45472
Mitre link : CVE-2025-45472
CVE.ORG link : CVE-2025-45472
JSON object : View
Products Affected
lumigo
- autodeploy-layer
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource