logo

AWS CDK Risk: Exploiting a Missing S3 Bucket Allow Takeover

ID: 7e4d630d-37f5-5c88-9fc5-69d831667fd0

STIX ID: report--7e4d630d-37f5-5c88-9fc5-69d831667fd0

Feed Name: Aqua Security Blog

Threat Score
72/100

Date Published: 2024-10-24

Date Updated: 2026-04-26

...
...

Aqua Security disclosed that predictable AWS CDK staging S3 bucket names (cdk-{qualifier}-assets-{account}-{region}) can be claimed by attackers when a user deletes their bucket, allowing the attacker to modify CloudFormation templates and inject an administrative role to achieve full account takeover; AWS patched the FilePublishingRole condition in CDK v2.149.0 and notified customers, but users who bootstrapped with v2.148.1 or earlier must re-run bootstrap or apply IAM conditions to mitigate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.