Vulnerability Bulletins

Issue with AWS Directory Service EnableRoleAccess


System information

   
Affected software AmazonWS

Description

Initial Publication Date: 06/14/2023 4:30PM PDT A researcher recently reported an issue in AWS Directory Service which would have enabled customer’s IAM principals, who are allowed to call the “EnableRoleAccess” API, to enable role access on the directory user even if that IAM principal did not have the “iam:passrole” permission. This specific issue would only occur if the calling IAM principal had permissions to call “EnableRoleAccess” API and would be

More info:

https://aws.amazon.com/security/security-bulletins/AWS-2023-003/

Standar resources

Property Value
CVE

Version history

Version Comments Date
1.0 Advisory issued 2023-06-16
Ministerio de Defensa
CNI
CCN
CCN-CERT