Boletines de Vulnerabilidades

Reported AWS Glue Issue

   
Software afectado AmazonWS
 
Initial Publication Date: 2022/01/13 13:00 PST A security researcher recently reported an issue that allowed them to take actions as the AWS Glue service. Utilizing an AWS Glue feature, researchers obtained credentials specific to the service itself, and an AWS-internal misconfiguration permitted the researchers to use these credentials as the AWS Glue service. There is no way that this could have been used to affect customers who do not use the AWS Glue service. No customer action is required.

More info:

https://aws.amazon.com/security/security-bulletins/AWS-2022-002/