Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Hulumi: Policy packs bypassed by a forged Pulumi-URN logical name
Vulnerability Description
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, policy packs can be bypassed by a forged Pulumi-URN logical name. This issue has been patched in version 1.4.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N
Vulnerability Type
保护机制失效
Vulnerability Title
Kerberosmansour Hulumi 处理逻辑错误漏洞
Vulnerability Description
Kerberosmansour Hulumi是Kerberosmansour个人开发者的一个面向Pulumi的云基础设施安全工具包。 Kerberosmansour Hulumi 1.4.0之前版本存在处理逻辑错误漏洞,该漏洞源于策略包可被伪造的Pulumi-URN逻辑名称绕过。
CVSS Information
N/A
Vulnerability Type
N/A