Impact
An unknown function within the AWS GitHub OIDC Deployment Helper Script in mocknest-serverless exposes an improper privilege management flaw. Manipulation of deployment/aws/shared/github-oidc-role.yaml can lead to unauthorized privilege escalation, allowing an attacker to assume higher permissions than intended. The vulnerability is classified under CWE-266 and CWE-269, indicating weaknesses in privilege granting and policy configuration.
Affected Systems
The issue affects elenavanengelenmaslova mocknest-serverless version 0.9.0, specifically the github-oidc-role.yaml file used during AWS GitHub OIDC deployment. No other versions have been identified as vulnerable in the current data.
Risk and Exploitability
The CVSS score of 5.1 denotes moderate risk, and the EPSS score is not available, suggesting limited publicly known exploitation. The vulnerability can be triggered remotely through manipulation of the script configuration. It is not listed in the CISA KEV catalog, indicating no confirmed active exploitation at the time of this analysis. Given the remote nature and potential for privilege escalation, organizations should regard this as a non-trivial risk, especially in environments where OIDC roles are critical for service access.
OpenCVE Enrichment