No keys attached: Exploring GitHub-to-AWS keyless authentication flaws
ID: 50394d48-4c7a-5267-a7ed-876de1c27b75
STIX ID: report--50394d48-4c7a-5267-a7ed-876de1c27b75
Feed Name: Datadog Security Labs
Datadog Security Labs details an attack surface in GitHub Actions-to-AWS OIDC setups where IAM trust policies omit or overwrite the JWT subject condition, enabling any GitHub Action to assume vulnerable roles. Using OSINT and automated GitHub Actions token requests, researchers identified hundreds of exposed role ARNs and demonstrated an instance in a UK Government Digital Service account that allowed access to private mirrored repositories; the issue was responsibly disclosed and remediated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
