Impact
Based on the updated description, the vulnerability in Hulumi allows an attacker to bypass IAM‑role policy checks when the role trusts multiple OIDC providers. This flaw corresponds to CWE‑697, an incorrect enforcement of permissions, and by manipulating or adding an OIDC provider that the role accepts, the attacker can obtain permissions that should have been denied, enabling unauthorized access to cloud resources. This bypass is a classic privilege escalation flaw and directly compromises the integrity and confidentiality of the infrastructure managed with Pulumi.
Affected Systems
The affected product is Hulumi released by kerberosmansour. All releases prior to version 1.4.0 are impacted, as the fix was backported and shipped in 1.4.0. Systems that depend on earlier versions of Hulumi for provisioning IAM roles are at risk.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity, but the EPSS score of less than 1 % shows that the likelihood of exploitation in the wild is currently low. It is not listed in the CISA KEV catalog. Based on the updated description, the likely attack vector is an attacker who can control or compromise an OIDC provider that is trusted by a role; once that provider is leveraged, the policy checks are coerced and the attacker can elevate privileges.
OpenCVE Enrichment
Github GHSA