Boletines de Vulnerabilidades

Reported AWS CloudFormation Issue

   
Software afectado AmazonWS
 
Initial Publication Date: 2022/01/13 13:00 PST Security researchers recently identified and reported an issue in AWS CloudFormation. Specifically, the reported issue was in the AWS CloudFormation service itself, which allowed viewing of some local configuration files on an AWS-internal host or attempted unauthenticated HTTP GET requests from the same host. The researchers utilized the HTTP GET capability to obtain a set of locally accessible credentials specific to the host. Neither the local

More info:

https://aws.amazon.com/security/security-bulletins/AWS-2022-001/