Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
HULUMI-H5 bypass via decoy sibling resources targeting a different bucket
Vulnerability Description
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, there is a bypass via decoy sibling resources targeting a different bucket. This issue has been patched in version 1.4.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:L
Vulnerability Type
访问控制不恰当
Vulnerability Title
Kerberosmansour Hulumi 权限许可和访问控制问题漏洞
Vulnerability Description
Kerberosmansour Hulumi是Kerberosmansour个人开发者的一个面向Pulumi的云基础设施安全工具包。 Kerberosmansour Hulumi 1.4.0之前版本存在权限许可和访问控制问题漏洞,该漏洞源于通过诱饵兄弟资源绕过访问控制,针对不同bucket。
CVSS Information
N/A
Vulnerability Type
N/A