Boletines de Vulnerabilidades

Issue with AWS Directory Service EnableRoleAccess


Información sobre el sistema

   
Software afectado AmazonWS

Descripción

Initial Publication Date: 06/14/2023 4:30PM PDT A researcher recently reported an issue in AWS Directory Service which would have enabled customer’s IAM principals, who are allowed to call the “EnableRoleAccess” API, to enable role access on the directory user even if that IAM principal did not have the “iam:passrole” permission. This specific issue would only occur if the calling IAM principal had permissions to call “EnableRoleAccess” API and would be

More info:

https://aws.amazon.com/security/security-bulletins/AWS-2023-003/

Identificadores estándar

Propiedad Valor
CVE

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2023-06-16

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT