A security issue exists in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
kubernetes aws-iam-authenticator |
Topics Security Off-Prem On-Prem Software Offbeat Vendor Voice Vendor Voice Resources Three vulnerabilities in one line of code
AWS fixed three authentication bugs present in one line of code in its IAM Authenticator for Kubernetes, used by the cloud giant's popular managed Kubernetes service Amazon EKS, that could allow an attacker to escalate privileges within a Kubernetes cluster. "I found several flaws in the authentication process that could bypass the protection against replay attacks or allow an attacker to gain higher permissions in the cluster by impersonating other identities," explained Lightspin's Director of...