Description
A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.
No analysis available yet.
Remediation
Vendor Workaround
Prior to upgrading, this vulnerability can be mitigated by not using the {{AccessKeyID}} template value to construct usernames.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6388 | A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges. |
Github GHSA |
GHSA-pp3f-98qg-5g75 | aws-iam-authenticator allow-listed IAM identity may be able to modify their username, escalate privileges before v0.5.9 |
References
History
No history.
Status: PUBLISHED
Assigner: kubernetes
Published:
Updated: 2024-09-16T22:25:39.286Z
Reserved: 2022-07-11T00:00:00.000Z
Link: CVE-2022-2385
No data.
Status : Modified
Published: 2022-07-12T19:15:08.487
Modified: 2024-11-21T07:00:53.143
Link: CVE-2022-2385
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA