A security community success story of mitigating a misconfiguration
ID: 4d4dd51b-4bbf-51d9-95e0-ed146878c9f3
STIX ID: report--4d4dd51b-4bbf-51d9-95e0-ed146878c9f3
Feed Name: Wiz Blog
This report describes a widespread misconfiguration in AWS IAM role trust policies for GitHub Actions OIDC integrations where the absence of the 'sub' condition allowed any GitHub repository to assume vulnerable roles, potentially enabling account takeover. Researchers and vendors identified the issue—exacerbated by a Terraform JSON handling quirk and copied tutorials—then coordinated mitigations including Terraform warnings/rules, AWS console UI changes, customer notifications, and eventual enforcement requiring the 'sub' condition.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
