C
月内に
Unit 42は、AWS AgentCore Harnessのデフォルト設定において、プロンプトインジェクションを通じてAgentCore Identityで管…
📌 一言でいうと
Unit 42は、AWS AgentCore Harnessのデフォルト設定において、プロンプトインジェクションを通じてAgentCore Identityで管理される平文の認証情報を窃取できる脆弱性を発見しました。攻撃者はエージェントの動作を操作し、アイデンティティ保管庫から機密情報を抽出させることが可能です。この問題は、AIエージェントの権限管理と実行環境の分離が不十分であることに起因しています。
🔍該当判定
- AWS AgentCore Harness を利用してAIエージェントを構築・運用している
- AWS AgentCore Identity を利用して、AIエージェント用の認証情報(パスワードやAPIキー)を管理している
- AIエージェントから MCP (Model Context Protocol) サーバーへの連携設定を行っている
上記いずれにも該当しない → 静観でOK
✅該当時の対応
1. AgentCore Harnessのデフォルト設定を見直し、最小権限の原則を適用すること。 2. プロンプトインジェクション対策として、入力バリデーションと出力フィルタリングを強化すること。 3. エージェントがアクセスできる認証情報の範囲を厳格に制限し、機密情報の露出を最小限に抑えること。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】AWS AgentCore Harness における認証情報漏洩リスクについて
お疲れさまです。AWS AgentCore Harnessに関するセキュリティリスクの情報共有です。
■ 概要
AWS AgentCore Harnessのデフォルト設定において、プロンプトインジェクション攻撃により、AgentCore Identityに保存されている平文の認証情報が窃取される可能性があることが報告されました。AIエージェントの制御を奪われることで、アイデンティティ保管庫からのデータ抽出が可能になります。
■ 影響範囲
- AWS AgentCore Harness および AgentCore Identity を利用している環境
■ 対応手順
1. エージェントに割り当てられているIAMロールおよび権限が最小限であるか確認してください。
2. AgentCore Identityで管理されるシークレットへのアクセス制御を再評価してください。
3. ユーザー入力がエージェントの指示に直接影響を与えないよう、ガードレール等の対策を検討してください。
■ 参考情報
- Unit 42 Research: A Vault with a Heap-View
対応優先度: 高
対応期限: 速やかに確認
お疲れさまです。AWS AgentCore Harnessに関するセキュリティリスクの情報共有です。
■ 概要
AWS AgentCore Harnessのデフォルト設定において、プロンプトインジェクション攻撃により、AgentCore Identityに保存されている平文の認証情報が窃取される可能性があることが報告されました。AIエージェントの制御を奪われることで、アイデンティティ保管庫からのデータ抽出が可能になります。
■ 影響範囲
- AWS AgentCore Harness および AgentCore Identity を利用している環境
■ 対応手順
1. エージェントに割り当てられているIAMロールおよび権限が最小限であるか確認してください。
2. AgentCore Identityで管理されるシークレットへのアクセス制御を再評価してください。
3. ユーザー入力がエージェントの指示に直接影響を与えないよう、ガードレール等の対策を検討してください。
■ 参考情報
- Unit 42 Research: A Vault with a Heap-View
対応優先度: 高
対応期限: 速やかに確認
Subject: [Security Advisory] Credential Exfiltration Risk in AWS AgentCore Harness
Dear IT/Security Team,
We are sharing information regarding a security vulnerability identified in AWS AgentCore Harness.
■ Overview
Unit 42 has discovered that default configurations in AWS AgentCore Harness may allow attackers to exfiltrate plaintext credentials managed by AgentCore Identity via prompt injection. Attackers can manipulate the agent's execution flow to access the identity vault.
■ Scope
- Environments utilizing AWS AgentCore Harness and AgentCore Identity.
■ Mitigation Steps
1. Review and enforce the principle of least privilege for IAM roles assigned to agents.
2. Re-evaluate access controls for secrets stored within AgentCore Identity.
3. Implement robust input validation and output filtering (guardrails) to prevent prompt injection.
■ Reference
- Unit 42 Research: A Vault with a Heap-View
Priority: High
Deadline: Immediate review recommended
Dear IT/Security Team,
We are sharing information regarding a security vulnerability identified in AWS AgentCore Harness.
■ Overview
Unit 42 has discovered that default configurations in AWS AgentCore Harness may allow attackers to exfiltrate plaintext credentials managed by AgentCore Identity via prompt injection. Attackers can manipulate the agent's execution flow to access the identity vault.
■ Scope
- Environments utilizing AWS AgentCore Harness and AgentCore Identity.
■ Mitigation Steps
1. Review and enforce the principle of least privilege for IAM roles assigned to agents.
2. Re-evaluate access controls for secrets stored within AgentCore Identity.
3. Implement robust input validation and output filtering (guardrails) to prevent prompt injection.
■ Reference
- Unit 42 Research: A Vault with a Heap-View
Priority: High
Deadline: Immediate review recommended