Executive brief
The AWS CDK CLI is a command-line tool that developers use to deploy cloud infrastructure code to AWS. Under certain conditions, when using custom credential plugins that return temporary credentials with an expiration time, the CLI prints sensitive AWS access keys and session tokens to the console output. Any user who can see the console or terminal output gains access to valid AWS credentials.
Technical details
The vulnerability is a credential exposure issue (CWE-497) in the AWS CDK CLI that occurs when custom credential plugins return credentials with an expiration property. The CLI unintentionally prints these credentials to console output instead of handling them securely. The attack vector is local; only users with access to the machine where the CDK CLI was executed can view the exposed credentials. Exploitation requires the developer to use a credential plugin configured to return temporary credentials with an expiration property—plugins without the expiration property are unaffected. An attacker with console access can extract valid AWS credentials and use them to authenticate to AWS. The issue was introduced in version 2.172.0 and patched in version 2.178.2.
Affected products
- AWS CDK CLI >=2.172.0, <2.178.2
- AWS aws-cdk >=2.172.0, <2.178.2
Timeline
- 2025-03-21: disclosed: Vulnerability published as GHSA-v63m-x9r9-8gqp
- 2025-03-21: patched: Fix released in version 2.178.2