A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6388 | A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges. |
Github GHSA |
GHSA-pp3f-98qg-5g75 | aws-iam-authenticator allow-listed IAM identity may be able to modify their username, escalate privileges before v0.5.9 |
Fixes
Solution
No solution given by the vendor.
Workaround
Prior to upgrading, this vulnerability can be mitigated by not using the {{AccessKeyID}} template value to construct usernames.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: kubernetes
Published:
Updated: 2024-09-16T22:25:39.286Z
Reserved: 2022-07-11T00:00:00
Link: CVE-2022-2385
No data.
Status : Modified
Published: 2022-07-12T19:15:08.487
Modified: 2024-11-21T07:00:53.143
Link: CVE-2022-2385
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA