Impact
Hulumi’s drift detection logic incorrectly classified adapter failures as "all clear" for up to six hours or elevated ordinary provider version changes to high‑severity incidents. The result is that legitimate attacks can be hidden or benign changes can trigger unnecessary alerts, undermining confidence in any downstream incident workflows that rely on the drift verdict. This flaw aligns with improper state transition handling (CWE‑755).
Affected Systems
All deployments of the open‑source Hulumi tool produced by kerberosmansour that run drift detection in continuous integrations or scheduled jobs, specifically any version prior to the v1.4.0 release. The patch in v1.4.0 corrects the drift classifier behavior to ensure accurate verdicts.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity, but the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would need the capability to influence the drift detection process—such as provoking adapter errors or manipulating provider data—to exploit this flaw. The impact is limited to environments that depend on drift detection signals for incident gating.
OpenCVE Enrichment
Github GHSA