CodeBreach: Missing Regex Anchors Exposed AWS Console to Takeover
ID: 7879700f-82ec-5521-8e9e-c95db50ec756
STIX ID: report--7879700f-82ec-5521-8e9e-c95db50ec756
Feed Name: securityonline.info
Wiz Research disclosed “CodeBreach,” a critical supply-chain vulnerability in AWS CodeBuild where a missing ^ and $ in an ACTOR_ID regex allow-list let accounts with “superstring” GitHub IDs trigger privileged builds; researchers created such an account, bypassed the filter, and extracted credentials that could enable malicious code injection into the AWS JavaScript SDK. AWS patched the regex and hardening measures within 48 hours and reported no customer impact, while recommending organizations review CI/CD build gate configurations to prevent untrusted contributions from triggering privileged pipelines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
