logo

A security community success story of mitigating a misconfiguration

ID: 4d4dd51b-4bbf-51d9-95e0-ed146878c9f3

STIX ID: report--4d4dd51b-4bbf-51d9-95e0-ed146878c9f3

Feed Name: Wiz Blog

Threat Score
55/100

Date Published: 2023-09-08

Date Updated: 2026-05-01

...
...

This report describes a widespread misconfiguration in AWS IAM role trust policies for GitHub Actions OIDC integrations where the absence of the 'sub' condition allowed any GitHub repository to assume vulnerable roles, potentially enabling account takeover. Researchers and vendors identified the issue—exacerbated by a Terraform JSON handling quirk and copied tutorials—then coordinated mitigations including Terraform warnings/rules, AWS console UI changes, customer notifications, and eventual enforcement requiring the 'sub' condition.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.