AWS Cloud Development Kit flaw exposed accounts to full takeover
ID: bf1e8172-1c03-50f6-8c58-9d2629a88de6
STIX ID: report--bf1e8172-1c03-50f6-8c58-9d2629a88de6
Feed Name: The Register (Security)
AWS fixed a vulnerability in the open-source Cloud Development Kit (CDK) where predictable CDK staging S3 bucket names could be claimed by attackers (namesquatting/Bucket Monopoly), potentially allowing administrative access and full account takeover. Aqua researchers disclosed the issue; AWS patched it in CDK v2.149.0 and estimated ~1% of users were affected, advising users who bootstrapped with v2.148.1 or earlier to take remediation steps and avoid predictable bucket naming.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
