logo

AWS Cloud Development Kit flaw exposed accounts to full takeover

ID: bf1e8172-1c03-50f6-8c58-9d2629a88de6

STIX ID: report--bf1e8172-1c03-50f6-8c58-9d2629a88de6

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-10-24

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

AWS fixed a vulnerability in the open-source Cloud Development Kit (CDK) where predictable CDK staging S3 bucket names could be claimed by attackers (namesquatting/Bucket Monopoly), potentially allowing administrative access and full account takeover. Aqua researchers disclosed the issue; AWS patched it in CDK v2.149.0 and estimated ~1% of users were affected, advising users who bootstrapped with v2.148.1 or earlier to take remediation steps and avoid predictable bucket naming.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.