Avoiding mistakes with AWS OIDC integration conditions
ID: efeb057e-587a-5897-9670-7a68d3dbf7f5
STIX ID: report--efeb057e-587a-5897-9670-7a68d3dbf7f5
Feed Name: Wiz Blog
Threat Score
This report reviews insecure AWS OIDC integrations across many vendors, highlighting that omitting or misconfiguring IAM trust policy conditions (especially "sub" and "aud", though some vendors use other keys) can enable attackers to assume IAM roles and potentially take over accounts; it catalogs vendor behaviours, provides correct policy examples, and recommends adding both aud and sub (or vendor-specific) conditions and detection checks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
