Impact
The vulnerability allows attackers to bypass intended IAM boundary restrictions by exploiting a weakened Service Control Policy (SCP) template in hulumi deployments. This results in a privilege escalation scenario where an attacker can grant themselves additional permissions or create resources that should be disallowed, potentially leading to unauthorized data access, resource modification, or leakage. The weakness is classified as CWE-284, which relates to improper authorization controls.
Affected Systems
The affected product is hulumi from the vendor kerberosmansour. All releases before version 1.3.2 are impacted. The SCP template that facilitates tag-on-create bypasses is incorporated into these earlier versions, and the issue is resolved in releases starting with v1.3.2.
Risk and Exploitability
The CVSS score of 9.3 places this misconfiguration in the critical severity bracket. Although an EPSS score is not available, the complexity of the attack vector is low: an attacker with access to create or modify deployments can supply a malicious SCP template to gain elevated permissions. The vulnerability is not yet listed in CISA's KEV catalog, but the high CVSS and potential for widespread impact indicate a serious exploitation risk if the flawed SCP template is used in downstream deployments.
OpenCVE Enrichment