Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-35165— AWS CDK EKS overly permissive trust policies

Quick assessment

Affected
aws aws-cdk
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

AWS Cloud Development Kit是一个开源软件开发框架,用于在代码中定义云基础设施并通过 AWS CloudFormation 进行配置。 AWS Cloud Development Kit存在安全漏洞,该漏洞源于eks.Cluster` 和eks.FargateCluster创建的两个角色具有过于宽松的信任策略。受影响的产品和版本:AWS Cloud Development Kit aws-cdk/aws-eks 1.57.0及之后版本, 1.202.0之前版本;aws-cdk-lib

CVSS 6.6 · Medium EPSS 0.90% · P58

Possible ATT&CK Techniques 1 AI

T1528 · Steal Application Access Token
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-35165

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
AWS CDK EKS overly permissive trust policies
Source: CVE Program / CVE List V5
Vulnerability Description
AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through AWS CloudFormation. In the packages `aws-cdk-lib` 2.0.0 until 2.80.0 and `@aws-cdk/aws-eks` 1.57.0 until 1.202.0, `eks.Cluster` and `eks.FargateCluster` constructs create two roles, `CreationRole` and `default MastersRole`, that have an overly permissive trust policy. The first, referred to as the `CreationRole`, is used by lambda handlers to create the cluster and deploy Kubernetes resources (e.g `KubernetesManifest`, `HelmChart`, ...) onto it. Users with CDK version higher or equal to 1.62.0 (including v2 users) may be affected. The second, referred to as the `default MastersRole`, is provisioned only if the `mastersRole` property isn't provided and has permissions to execute `kubectl` commands on the cluster. Users with CDK version higher or equal to 1.57.0 (including v2 users) may be affected. The issue has been fixed in `@aws-cdk/aws-eks` v1.202.0 and `aws-cdk-lib` v2.80.0. These versions no longer use the account root principal. Instead, they restrict the trust policy to the specific roles of lambda handlers that need it. There is no workaround available for CreationRole. To avoid creating the `default MastersRole`, use the `mastersRole` property to explicitly provide a role.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5
Vulnerability Title
AWS Cloud Development Kit 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
AWS Cloud Development Kit是一个开源软件开发框架,用于在代码中定义云基础设施并通过 AWS CloudFormation 进行配置。 AWS Cloud Development Kit存在安全漏洞,该漏洞源于eks.Cluster` 和eks.FargateCluster创建的两个角色具有过于宽松的信任策略。受影响的产品和版本:AWS Cloud Development Kit aws-cdk/aws-eks 1.57.0及之后版本, 1.202.0之前版本;aws-cdk-lib
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
aws aws-cdk aws-cdk-lib >= 2.0.0, < 2.80.0 -

II. Public POCs for CVE-2023-35165

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-35165

请登录查看更多情报信息。

Vendor Advisories for CVE-2023-35165 (1)

Other References for CVE-2023-35165 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2023-35165

No comments yet


Leave a comment