Vulnerability Bulletins

Issue with AWS Directory Service EnableRoleAccess

System information

Affected software AmazonWS


Initial Publication Date: 06/14/2023 4:30PM PDT A researcher recently reported an issue in AWS Directory Service which would have enabled customer’s IAM principals, who are allowed to call the “EnableRoleAccess” API, to enable role access on the directory user even if that IAM principal did not have the “iam:passrole” permission. This specific issue would only occur if the calling IAM principal had permissions to call “EnableRoleAccess” API and would be

More info:

Standar resources

Property Value

Version history

Version Comments Date
1.0 Advisory issued 2023-06-16
Ministerio de Defensa