VDB

GCVE-110-CLOUD-2024-0001

GCVE-110-CLOUD-2024-0001
Advisory Published
Vulnetix · Advisory published December 29, 2024
AWS Neuron SDK has reintroduced a dependency confusion vulnerability three times in four years. The issue stems from using the --extra-index-url parameter in pip install commands, which allows potential installation of malicious packages from PyPI instead of AWS's private repository. Despite previous reports, AWS has not fully addressed the problem, leaving new packages vulnerable to exploitation.

Affected Products

VendorProductVersionsPlatforms
AWSCloud Services
AWSNeuron SDK

Browse GCVE Records

75,828 records in the GCVE database · Updated August 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›