Showing 1 vulnerability on this page for EMR

Signals CISA KEV Ransomware Nuclei
Amazon vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Privilege escalation issue in Amazon EMR Secret Agent component

Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ directory. A user with access to this directory and another account can potentially decrypt the keys and escalate to higher privileges. Users are advised to upgrade to Amazon EMR version 7.5 or higher. For Amazon EMR releases between 6.10 and 7.4, we strongly recommend that you run the bootstrap script and RPM files with the fix provided in the location below.

CWE-257Aug 13, 2025
CVSS9.0v4.0EPSS0.333%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX