Cloud Security · Amazon AWS Amplify CLI

AWS Amplify CLI Flaw (CVE-2024-28056) Could Expose IAM Roles to Unauthorized Assumption

Amazon AWS Amplify CLI versions before 12.10.1 incorrectly configure the role trust policy of IAM roles tied to Amplify projects: when the Authentication component is removed, a Condition property is dropped while "Effect":"Allow" remains, leaving sts:AssumeRoleWithWebIdentity available without conditions. Projects built between August 2019 and January 2024 from which an authorized AWS user removed the Authentication component could have allowed threat actors to assume the role and gain unauthorized access to AWS resources.