Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2025-12779

Gravedad CVSS v4.0:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
05/11/2025
Última modificación:
10/11/2025

Descripción

*** Pendiente de traducción *** Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8, may expose the authentication token for DCV-based WorkSpaces to other local users on the same client machine. Under certain circumstances, a local user may be able to extract another local user&amp;#39;s authentication token from the shared client machine and access their WorkSpace.<br /> <br /> To mitigate this issue, users should upgrade to the Amazon WorkSpaces client for Linux version 2025.0 or later.