Impact
@hulumi/baseline, a JavaScript library used for infrastructure as code, contains a bug that allows a malicious actor to tamper with AWS CloudTrail event selectors. The library fails to fully detect selector changes, resulting in audit logging coverage gaps. This weakness can be exploited to modify the event selectors without alerting monitoring systems, effectively erasing evidence of configuration changes and enabling further malicious activities.
Affected Systems
The vulnerability affects all installations of @hulumi/baseline older than version 1.3.2. Any environment that relies on this library to enforce or validate AWS CloudTrail selector configurations is susceptible.
Risk and Exploitability
The CVSS score of 8.7 classifies the flaw as high severity. Although the EPSS score is not available, the lack of a KEV listing does not diminish the risk to systems that rely on robust audit trails. Attackers would need to execute or influence code that uses the impacted baseline library to modify CloudTrail selectors, but once the modification occurs, existing detection mechanisms may not notice the change. The likely attack vector involves manipulating configuration scripts or deployment artifacts that employ @hulumi/baseline to manage CloudTrail settings.
OpenCVE Enrichment