Impact
Hulumi is an open‑source toolkit that ships secure‑by‑default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, an attacker could bypass policy packs by forging a Pulumi‑URN logical name. The flaw, classified as CWE‑693, involves improper authentication or authorization checks that allow crafted URNs to satisfy policy evaluation. It was remedied in version 1.4.0.
Affected Systems
The affected vendor is Kerberos Mansour, product Hulumi. All releases prior to version 1.4.0 are vulnerable. The patch providing protection was released as part of the 1.4.0 release.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation at the time of analysis. Hulumi is not listed in CISA’s KEV catalog. Based on the description, the attack vector appears to be a forgery of logical names within a Pulumi deployment, which would be exercised when the tool processes user‑specified resources. The attacker would need to supply a crafted Pulumi‑URN during deployment; the vulnerability is not exploitable over a network interface without such a deployment context.
OpenCVE Enrichment
Github GHSA