Cloud Security
Cloud Security · Amazon AWS Amplify CLI
AWS Amplify CLI Flaw (CVE-2024-28056) Could Expose IAM Roles to Unauthorized Assumption
Amazon AWS Amplify CLI versions before 12.10.1 incorrectly configure the role trust policy of IAM roles tied to Amplify projects: when the Authentication component is removed, a Condition property is dropped while "Effect":"Allow" remains, leaving sts:AssumeRoleWithWebIdentity available without conditions. Projects built between August 2019 and January 2024 from which an authorized AWS user removed the Authentication component could have allowed threat actors to assume the role and gain unauthorized access to AWS resources.
Read the original coverage at National Vulnerability Database (NVD)
Captured 23 minutes ago