Impact
This vulnerability allows attackers to submit spoofed parent evidence during policy evaluation, circumventing SecureBucket parent checks. The issue stems from improper access control and enables malicious actors to validate storage buckets that should be blocked, potentially exposing data or granting unauthorized bucket access.
Affected Systems
The affected product is the hulumi/policies library, specifically all releases before version 1.3.2. Any Node.js project that depends on these pre‑1.3.2 releases and uses the library for Cloud bucket policy enforcement is vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. EPSS is not available, so exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by sending crafted evidence to the policy validator API, a form of remote request that bypasses parent checks. The likely attack vector is through the policy engine’s API endpoint, requiring knowledge of the expected evidence format and access to the validation service. While no public exploit is documented, the combination of a high CVSS score and the potential for data exposure makes the risk high.
OpenCVE Enrichment