Impact
Hulumi is an open‑source toolkit that ships secure‑by‑default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, a bypass exists that allows decoy sibling resources to target a bucket other than the one intended, potentially leading to unintended bucket access. The issue was addressed in release 1.4.0.
Affected Systems
The open‑source Hulumi collection developed by Kerberosmansour. Versions prior to 1.4.0 contain the vulnerability; the issue was fixed in release 1.4.0 and later.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity risk, while the EPSS score of less than 1% shows a low but non‑zero likelihood of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker who can influence Pulumi deployment scripts or configurations can add decoy sibling resources targeting a different bucket, thereby exploiting the unrestricted access rights in older Hulumi versions.
OpenCVE Enrichment
Github GHSA