Related Vulnerabilities: CVE-2022-2385  

A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.

Description

The MITRE CVE dictionary describes this issue as:

A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.

Additional Information

  • Bugzilla 2107036: CVE-2022-2385 aws-iam-authenticator: AccessKeyID validation bypass
  • FAQ: Frequently asked questions about CVE-2022-2385