logo

CloudTrail Logging Evasion: Where Policy Size Matters

ID: fdf7bc45-3a4e-5f95-ab76-f0daa8b36bbf

STIX ID: report--fdf7bc45-3a4e-5f95-ab76-f0daa8b36bbf

Feed Name: Cloud Chronicles

Threat Score
50/100

Date Published: 2025-05-29

Date Updated: 2026-07-29

Author: Abian Morina

...
...

Permiso Security discovered and disclosed an AWS CloudTrail logging evasion vulnerability where IAM policies expanded with excessive whitespace (roughly 102,401–131,072 characters) are successfully created but their content is omitted from CloudTrail requestParameters, producing an audit blind spot; the report includes technical reproduction steps, impact analysis, a disclosure timeline with AWS, and recommendations to monitor for 'requestParameters too large' omissions until AWS implements a fix.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.